Logo
componentgnuplot
Name
gnuplot
Version
5.4.3
Type
library
Description
Gnuplot is a portable command-line driven graphing utility
Licenses
gnuplot
PURL
-
CPE
cpe:2.3:*:gnuplot:gnuplot:5.4.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
5.4.3
master
6.0.3

Patches#


#
Title
Author
Resolve
1
Add configure option to find qt5 native tools
=?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
2
hpgl: font name parsing overruns the string by one char
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-3359
3
reduce build to conversion tools for native build
=?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
4
Use native tools to build docs
=?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
5
use snprintf to protect against garbage user-supplied mouse
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-31178
6
guard against trying to format a huge number as a time
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-31179
7
Do not build demos
=?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
8
dumb: more stringent tests against y bound of dumb terminal
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-31177
9
guard against invalid read from plot->labels
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-31176
10
x11: protect against double fclose() if two errors in a row
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-31181
11
canvas: handle nonlinear x2 or y2 axis with an incomplete
Ethan A Merritt <merritt@u.washington.edu>
CVE-2025-31180

Vulnerabilities#


Name
Analysis
Description
Patched
A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.
Patched
A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.
Patched
A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.
Patched
A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.
Patched
A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.
Patched
gnuplot is affected by a heap buffer overflow at function utf8_copy_one.
Patched
A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.