CVE-2020-25412: Critical severity gnuplot vulnerability
Published Sep 16, 2020
·Updated
comline() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.
Affected Software
2 affected components
Gnuplot Project Gnuplot=5.4.0
gnuplot gnuplot=5.4.0
Event History
Sep 16, 2020
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-25412?
CVE-2020-25412 is a vulnerability in gnuplot 5.4 that leads to an out-of-bounds write from strncpy() that may lead to arbitrary code execution.
2
How severe is CVE-2020-25412?
CVE-2020-25412 has a severity value of 9.8, indicating it is critical.
3
What software versions are affected by CVE-2020-25412?
Gnuplot version 5.4.0 is affected by CVE-2020-25412.
4
How can I fix CVE-2020-25412?
There is currently no known fix or patch available for CVE-2020-25412. It is recommended to update to a version of gnuplot that is not affected by this vulnerability when available.
5
Where can I find more information about CVE-2020-25412?
More information about CVE-2020-25412 can be found at the following link: https://sourceforge.net/p/gnuplot/bugs/2303/