A stack-based buffer overflow (CWE-121) affects GMT (Generic Mapping Tools) versions 6.6.0 and prior, triggered by a specially crafted long string passed as a dataset identifier. Rated High (CVSS 7.8), this vulnerability requires local access or user interaction to exploit, but can lead to a system crash or arbitrary code execution. There is currently no evidence of active exploitation, nor are public exploit tools available. Community attention is very low, with only a single mention observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.6.0CPE matchmatch criteria | cpe:2.3:a:generic-mapping-tools:gmt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.