An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-data" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-doc" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-nox" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-nox-dbgsym" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-qt" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-qt-dbgsym" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-tex" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-x11" }, { "binary_version": "4.6.6-3ubuntu0.1", "binary_name": "gnuplot-x11-dbgsym" } ] }