CVE-2026-33147

GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt_remote_dataset_id function within src/gmt_remote.c. This issue occurs when a specially crafted long string is passed as a dataset identifier (e.g., via the which module), leading to a crash or potential arbitrary code execution. This issue has been patched via commit 0ad2b49.
Configurations

Configuration 1 (hide)

cpe:2.3:a:generic-mapping-tools:gmt:*:*:*:*:*:*:*:*

History

27 Mar 2026, 21:07

Type Values Removed Values Added
References () https://github.com/GenericMappingTools/gmt/commit/0ad2b491470df82c9ec1139dcbd70502fa28a082 - () https://github.com/GenericMappingTools/gmt/commit/0ad2b491470df82c9ec1139dcbd70502fa28a082 - Patch
References () https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg - () https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg - Exploit, Vendor Advisory
First Time Generic-mapping-tools gmt
Generic-mapping-tools
CPE cpe:2.3:a:generic-mapping-tools:gmt:*:*:*:*:*:*:*:*

25 Mar 2026, 15:16

Type Values Removed Values Added
Summary
  • (es) GMT es una colección de código abierto de herramientas de línea de comandos para manipular conjuntos de datos geográficos y cartesianos. En versiones desde la 6.6.0 y anteriores, se identificó una vulnerabilidad de desbordamiento de búfer basado en pila en la función gmt_remote_dataset_id dentro de src/gmt_remote.c. Este problema ocurre cuando una cadena larga especialmente diseñada se pasa como un identificador de conjunto de datos (p. ej., a través del módulo which), lo que lleva a un fallo o a una potencial ejecución de código arbitrario. Este problema ha sido parcheado mediante el commit 0ad2b49.
References () https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg - () https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg -

20 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 21:17

Updated : 2026-03-27 21:07


NVD link : CVE-2026-33147

Mitre link : CVE-2026-33147

CVE.ORG link : CVE-2026-33147


JSON object : View

Products Affected

generic-mapping-tools

  • gmt
CWE
CWE-121

Stack-based Buffer Overflow