An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.
| Software | From | Fixed in |
|---|---|---|
| gnuplot / gnuplot | 5.2.5 | 5.2.5.x |
| debian / debian_linux | 8.0 | 8.0.x |
| opensuse / leap | 15.0 | 15.0.x |