CVE-2025-31180: Gnuplot: gnuplot segmentation fault on canvas_text
A flaw was found in gnuplot. The CANVAStext() function may lead to a segmentation fault and cause a system crash.
Other sources
gnuplot 6.1 is affected by SEGV when executing function CANVAStext. This may result in local code execution.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31180?
CVE-2025-31180 is classified as a critical vulnerability due to its potential for local code execution and system crashes.
How do I fix CVE-2025-31180?
To mitigate the effects of CVE-2025-31180, update gnuplot to the latest version available that contains the security patches.
What impact does CVE-2025-31180 have on gnuplot users?
CVE-2025-31180 may lead to segmentation faults in gnuplot, resulting in application crashes and possible execution of arbitrary code.
Can CVE-2025-31180 be exploited remotely?
CVE-2025-31180 primarily allows for local exploitation through crafted input, requiring local access to trigger the vulnerability.
Which versions of gnuplot are affected by CVE-2025-31180?
Gnuplot version 6.1 is specifically mentioned as being affected by the CVE-2025-31180 vulnerability.