Debian Security Advisory
DLA-105-1 graphviz -- LTS security update
- Date Reported:
- 11 Dec 2014
- Affected Packages:
- graphviz
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 772648.
In Mitre's CVE dictionary: CVE-2014-9157. - More information:
-
Joshua Rogers discovered a format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz, a rich set of graph drawing tools. An attacker could use this flaw to cause graphviz to crash or possibly execute arbitrary code.
For Debian 6
Squeeze
, these issues have been fixed in graphviz version 2.26.3-5+squeeze3