Double Free in Gnuplot - CVE-2020-25559
Published: September 16, 2020 / Updated: September 22, 2020
Vulnerability identifier: #VU46917
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25559
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.
Affected software
Gnuplot
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
gnuplot (Ubuntu package)
gnuplot-debugsource
gnuplot-debuginfo
gnuplot
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
gnuplot (Ubuntu package)
gnuplot-debugsource
gnuplot-debuginfo
gnuplot
How to mitigate CVE-2020-25559
Install update from vendor's website.
gnuplot (Ubuntu package) - addressed in versions 4.6.4-2ubuntu0.1~esm1, 4.6.6-3ubuntu0.1+esm1, 5.2.2+dfsg1-2ubuntu1+esm1, 5.2.8+dfsg1-2ubuntu0.1~esm1
gnuplot-debugsource - update to 4.6.5-3.6.1
gnuplot-debuginfo - update to 4.6.5-3.6.1
gnuplot - update to 4.6.5-3.6.1
gnuplot-debugsource - update to 4.6.5-3.6.1
gnuplot-debuginfo - update to 4.6.5-3.6.1
gnuplot - update to 4.6.5-3.6.1