Buffer overflow in Gnuplot - CVE-2018-19492
Published: November 28, 2018
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists in the cairo.trm source code file due to boundary error when the pngcairo terminal is used. A local attacker can make a specially crafted request that sa malicious argument to be passed to the set font function, trigger memory corruption condition and cause a DoS condition or execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Ubuntu
Opensuse
gnuplot (Ubuntu package)
gnuplot-data (Ubuntu package)
gnuplot-nox (Ubuntu package)
gnuplot-qt (Ubuntu package)
gnuplot-tex (Ubuntu package)
gnuplot-x11 (Ubuntu package)
How to mitigate CVE-2018-19492
gnuplot-data (Ubuntu package) - update to 4.6.6-3ubuntu0.1
gnuplot-nox (Ubuntu package) - update to 4.6.6-3ubuntu0.1
gnuplot-qt (Ubuntu package) - update to 4.6.6-3ubuntu0.1
gnuplot-tex (Ubuntu package) - update to 4.6.6-3ubuntu0.1
gnuplot-x11 (Ubuntu package) - update to 4.6.6-3ubuntu0.1