Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agraph_t elements.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade graphviz | Jul 30, 2024 | Oct 14, 2008 |
| Gentoo Linux | — | Upgrade media-gfx/graphviz. | Oct 30, 2017 | Oct 14, 2008 |
| Suse | — | Upgrade graphviz-tclUpgrade graphviz-ocamlUpgrade graphvizUpgrade graphviz-sharpUpgrade graphviz-perlUpgrade graphviz-javaUpgrade graphviz-docUpgrade graphviz-gdUpgrade suse-releaseUpgrade graphviz-luaUpgrade graphviz-gnomeUpgrade graphviz-rubyUpgrade graphviz-phpUpgrade graphviz-guileUpgrade graphviz-develUpgrade graphviz-python | Feb 17, 2015 | Oct 14, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub