Debian Security Advisory

DLA-105-1 graphviz -- LTS security update

Date Reported:
11 Dec 2014
Affected Packages:
graphviz
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 772648.
In Mitre's CVE dictionary: CVE-2014-9157.
More information:

Joshua Rogers discovered a format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz, a rich set of graph drawing tools. An attacker could use this flaw to cause graphviz to crash or possibly execute arbitrary code.

For Debian 6 Squeeze, these issues have been fixed in graphviz version 2.26.3-5+squeeze3