OESA-2025-2154

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2154
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2154.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2025-2154
Upstream
Published
2025-09-05T12:42:47Z
Modified
2025-09-05T13:03:26.510393Z
Summary
gnuplot security update
Details

Gnuplot is a portable command-line driven graphing utility for Linux, OS/2, MS Windows, OSX, VMS, and many other platforms. The source code is copyrighted but freely distributed (i.e., you don't have to pay for it). It was originally created to allow scientists and students to visualize mathematical functions and data interactively, but has grown to support many non-interactive uses such as web scripting. It is also used as a plotting engine by third-party applications like Octave. Gnuplot has been supported and under active development since 1986.

Security Fix(es):

A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.(CVE-2025-31176)

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.(CVE-2025-31179)

A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.(CVE-2025-31180)

A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.(CVE-2025-31181)

A flaw was found in GNUPlot. A segmentation fault via IOstrinitstaticinternal may jeopardize the environment.(CVE-2025-3359)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP3 / gnuplot

Package

Name
gnuplot
Purl
pkg:rpm/openEuler/gnuplot&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.6-15.oe2203sp3

Ecosystem specific

{
    "x86_64": [
        "gnuplot-5.0.6-15.oe2203sp3.x86_64.rpm",
        "gnuplot-debuginfo-5.0.6-15.oe2203sp3.x86_64.rpm",
        "gnuplot-debugsource-5.0.6-15.oe2203sp3.x86_64.rpm"
    ],
    "src": [
        "gnuplot-5.0.6-15.oe2203sp3.src.rpm"
    ],
    "aarch64": [
        "gnuplot-5.0.6-15.oe2203sp3.aarch64.rpm",
        "gnuplot-debuginfo-5.0.6-15.oe2203sp3.aarch64.rpm",
        "gnuplot-debugsource-5.0.6-15.oe2203sp3.aarch64.rpm"
    ],
    "noarch": [
        "gnuplot-help-5.0.6-15.oe2203sp3.noarch.rpm"
    ]
}