cbcvebase.
CVE-2020-19491
published 2021-07-21

CVE-2020-19491: There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or…

PriorityP432high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.00%
59.2th percentile
There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

Affected

5 ranges
VendorProductVersion rangeFixed in
gnuplotgnuplot>= 0 < 4.6.4-2ubuntu0.1~esm14.6.4-2ubuntu0.1~esm1
gnuplotgnuplot>= 0 < 4.6.6-3ubuntu0.1+esm14.6.6-3ubuntu0.1+esm1
gnuplotgnuplot>= 0 < 5.2.2+dfsg1-2ubuntu1+esm15.2.2+dfsg1-2ubuntu1+esm1
gnuplotgnuplot>= 0 < 5.2.8+dfsg1-2ubuntu0.1~esm15.2.8+dfsg1-2ubuntu0.1~esm1
sam2p_projectsam2p

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.