CVE-2025-31179: Gnuplot: gnuplot segmentation fault on xstrftime
Published Mar 27, 2025
·Updated
A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.
Other sources
gnuplot 6.1 is affected by SEGV when executing function xstrftime. This may result in local code execution.
— Red Hat
Affected Software
5 affected components
gnuplot gnuplot
All of the following
gnuplot gnuplot<6.0.0
Any of the following
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
Event History
Mar 27, 2025
Data Sourced
via Red Hat·02:18 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31179?
CVE-2025-31179 has a high severity level due to the potential for local code execution and system crashes.
2
How do I fix CVE-2025-31179?
To fix CVE-2025-31179, you should upgrade gnuplot to the latest version that addresses this segmentation fault issue.
3
What is the impact of CVE-2025-31179?
The impact of CVE-2025-31179 includes a segmentation fault in the xstrftime() function, which can lead to a system crash.
4
Which versions of gnuplot are affected by CVE-2025-31179?
CVE-2025-31179 affects gnuplot version 6.1 specifically.
5
Can CVE-2025-31179 be exploited remotely?
CVE-2025-31179 is not considered a remote vulnerability as it requires local code execution.