CVE-2025-31178

CVSS 3.1 Score 6.2 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 476

Summary

CVE-2025-31178 is a newly discovered vulnerability affecting the GetAnnotateString() function in gnuplot. This issue can result in a segmentation fault and subsequent system crash. The flaw lies within the handling of certain input data, which if manipulated maliciously, can trigger the unintended behavior. This vulnerability may pose a significant risk, particularly in environments where gnuplot is used extensively, as it can lead to denial-of-service attacks or potentially more severe consequences. Users are strongly advised to apply the available patch or update to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux

Affected Vendors

  • Red Hat