CVE Vulnerabilities

CVE-2025-31178

NULL Pointer Dereference

Published: Mar 27, 2025 | Modified: Jul 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
GnuplotGnuplot*6.0.0 (excluding)
GnuplotUbuntudevel*
GnuplotUbuntuesm-apps/bionic*
GnuplotUbuntuesm-apps/focal*
GnuplotUbuntuesm-apps/jammy*
GnuplotUbuntuesm-apps/noble*
GnuplotUbuntuesm-apps/xenial*
GnuplotUbuntuesm-infra-legacy/trusty*
GnuplotUbuntufocal*
GnuplotUbuntujammy*
GnuplotUbuntunoble*
GnuplotUbuntuoracular*
GnuplotUbuntuplucky*
GnuplotUbuntuquesting*
GnuplotUbuntuupstream*

Potential Mitigations

References