7.8
CVSSv3

CVE-2017-9670

Published: 15/06/2017 Updated: 05/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an malicious user to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnuplot project gnuplot 5.2

Vendor Advisories

Debian Bug report logs - #864901 gnuplot: CVE-2017-9670: uninitialized stack variable vulnerability could lead to a Denial of Service Package: src:gnuplot; Maintainer for src:gnuplot is Debian Science Team <debian-science-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...
An uninitialized stack variable vulnerability in load_tic_series() in setc in gnuplot 52rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file ...