PT-2021-18188 · Gnuplot · Gnuplot

Published

2021-05-03

·

Updated

2022-05-03

·

CVE-2021-29369

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: gnuplot versions prior to 0.1.0
Description: The issue allows code execution via shell metacharacters in Gnuplot commands. This can be exploited by injecting malicious commands, potentially leading to unauthorized access or data compromise. The gnuplot package is used to draw charts and can be integrated with other tools like ps2pdf.
Recommendations: For versions prior to 0.1.0, update to version 0.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the input to Gnuplot commands to prevent shell metacharacter injection until a patch is applied.

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29369
GHSA-F2JW-PR2C-9X96

Affected Products

Gnuplot