PT-2021-18188 · Gnuplot · Gnuplot
Published
2021-05-03
·
Updated
2022-05-03
·
CVE-2021-29369
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
gnuplot versions prior to 0.1.0
Description:
The issue allows code execution via shell metacharacters in Gnuplot commands. This can be exploited by injecting malicious commands, potentially leading to unauthorized access or data compromise. The gnuplot package is used to draw charts and can be integrated with other tools like ps2pdf.
Recommendations:
For versions prior to 0.1.0, update to version 0.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the input to Gnuplot commands to prevent shell metacharacter injection until a patch is applied.
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnuplot