Segmentation Fault in GNUPlot Affects Red Hat Products
CVE-2025-3359

6.2MEDIUM

Key Information:

Summary

A critical flaw has been identified in GNUPlot that can lead to a segmentation fault through the IO_str_init_static_internal function. This vulnerability could have significant implications for the stable operation of the affected environments, as it may potentially allow for environment instability and unforeseen behavior during execution.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank ChenYiFan Liu for reporting this issue.
.