PT-2026-64167 · Gnuplot+1 · Gnuplot+1
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
gpsd versions prior to 3.27.6
Description
The
gpsprof utility contains a code injection flaw. An attacker controlling GPS input data can execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field. This field is inserted without sanitization into a gnuplot heredoc data block. By supplying a used value containing the string EOD, an attacker can terminate the heredoc prematurely and append gnuplot system() calls, leading to command execution as the user running gpsprof when the script is processed by gnuplot in polar mode.Recommendations
Update to the version containing commit 4c06658 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnuplot
Gpsd