Double Free in Gnuplot - CVE-2020-25559

 

Double Free in Gnuplot - CVE-2020-25559

Published: September 16, 2020 / Updated: September 22, 2020


Vulnerability identifier: #VU46917
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25559
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.


Affected software

Gnuplot
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
gnuplot (Ubuntu package)
gnuplot-debugsource
gnuplot-debuginfo
gnuplot

How to mitigate CVE-2020-25559

Install update from vendor's website.

gnuplot (Ubuntu package) - addressed in versions 4.6.4-2ubuntu0.1~esm1, 4.6.6-3ubuntu0.1+esm1, 5.2.2+dfsg1-2ubuntu1+esm1, 5.2.8+dfsg1-2ubuntu0.1~esm1
gnuplot-debugsource - update to 4.6.5-3.6.1
gnuplot-debuginfo - update to 4.6.5-3.6.1
gnuplot - update to 4.6.5-3.6.1

External References

Related Security Bulletins