Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: gnuplot Moderate Security Flaws CVE-2025-31176 to CVE-2025-3359

suse
Calendar Grey July 16, 2025
Dist Suse Esm H88
The latest release of gnuplot tackles a series of problems, focusing specifically on severe segmentation faults and vulnerabilities related to memory safety in OpenSUSE.
* bsc#1240325 * bsc#1240326 * bsc#1240327 * bsc#1240328 * bsc#1240329

Summary

## This update for gnuplot fixes the following issues: * CVE-2025-31176: invalid read leads to segmentation fault on plot3d_points (bsc#1240325). * CVE-2025-31177: improper bounds check leads to heap-buffer overflow on utf8_copy_one (bsc#1240326). * CVE-2025-31178: unvalidated user input leads to segmentation fault on GetAnnotateString (bsc#1240327). * CVE-2025-31179: improper verification of time values leads to segmentation fault on xstrftime (bsc#1240328). * CVE-2025-31180: unchecked invalid pointer access leads to segmentation fault on CANVAS_text (bsc#1240329). * CVE-2025-31181: double fclose() call leads to segmentation fault on X11_graphics (bsc#1240330). * CVE-2025-3359: out-of-bounds read when parsing font names may lead to a segmentation fault (bsc#1241684).

References

* bsc#1240325

* bsc#1240326

* bsc#1240327

* bsc#1240328

* bsc#1240329

* bsc#1240330

* bsc#1241684

Cross-

* CVE-2025-31176

* CVE-2025-31177

* CVE-2025-31178

* CVE-2025-31179

* CVE-2025-31180

* CVE-2025-31181

* CVE-2025-3359

CVSS scores:

* CVE-2025-31176 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-31176 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-31177 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-31178 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-31178 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-31179 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-31179 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Announcement ID: SUSE-SU-2025:01811-2
Release Date: 2025-07-16T14:49:36Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here