Buffer overflow in Gnuplot - CVE-2018-19492
Published: November 28, 2018
Gnuplot
Detailed vulnerability description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists in the cairo.trm source code file due to boundary error when the pngcairo terminal is used. A local attacker can make a specially crafted request that sa malicious argument to be passed to the set font function, trigger memory corruption condition and cause a DoS condition or execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.