PT-2026-26669 · Genericmappingtools · Gmt
Published
2026-03-20
·
Updated
2026-03-20
·
CVE-2026-33147
CVSS v3.1
7.3
High
| AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt remote dataset id function within src/gmt remote.c. This issue occurs when a specially crafted long string is passed as a dataset identifier (e.g., via the which module), leading to a crash or potential arbitrary code execution. This issue has been patched via commit 0ad2b49.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gmt