High severity7.8NVD Advisory· Published Nov 23, 2018· Updated Jun 17, 2026
CVE-2018-19492
CVE-2018-19492
Description
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- osv-coords7 versionspkg:rpm/opensuse/gnuplot&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/gnuplot&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gnuplot&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015pkg:rpm/suse/gnuplot&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/gnuplot&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/gnuplot&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/gnuplot&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
< 5.2.2-lp150.3.3.1+ 6 more
- (no CPE)range: < 5.2.2-lp150.3.3.1
- (no CPE)range: < 5.4.2-1.3
- (no CPE)range: < 5.2.2-3.3.29
- (no CPE)range: < 4.6.5-3.3.74
- (no CPE)range: < 4.6.5-3.3.74
- (no CPE)range: < 4.6.5-3.3.74
- (no CPE)range: < 4.6.5-3.3.74
Patches
Vulnerability mechanics
References
6- sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/nvdPatchThird Party Advisory
- sourceforge.net/p/gnuplot/bugs/2089/nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00066.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/11/msg00031.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/11/msg00035.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/4541-1/nvd
News mentions
0No linked articles in our index yet.