CVE-2018-19491: Buffer Overflow
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PSoptions function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19491?
CVE-2018-19491 has been classified as a medium severity vulnerability due to its potential to cause a buffer overflow.
How do I fix CVE-2018-19491?
To address CVE-2018-19491, update Gnuplot to a version later than 5.2.5 or apply the provided patches.
What systems are affected by CVE-2018-19491?
CVE-2018-19491 affects Gnuplot 5.2.5 and various Linux distributions that include this version.
Can CVE-2018-19491 be exploited remotely?
CVE-2018-19491 can potentially be exploited remotely if an attacker can supply crafted input to the vulnerable Gnuplot application.
What consequences can arise from CVE-2018-19491?
Successful exploitation of CVE-2018-19491 may allow an attacker to execute arbitrary code or crash the affected application.