graphviz: stack-based buffer overflow in yyerror()
Published Jan 10, 2014
9.3
HIGHCVSS 2.0
EPSS 4.89%
Description
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via a long line in a dot file.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
graphviz
Will not fix
Red Hat Enterprise Linux 7
graphviz
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | graphviz | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | graphviz | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of the graphviz package as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Low security impact and therefore it is not planned to be addressed in future updates. This issue did not affect the versions of the graphviz package as shipped with Red Hat Enterprise Linux 7.
References (16)
- http://seclists.org/oss-sec/2014/q1/28 mailing-listx_refsource_MLIST
- http://seclists.org/oss-sec/2014/q1/38 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/55666 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/56244 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-2843 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:024 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/64674 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2014-0978 Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=497274 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=1049165 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-1008 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90085 vdb-entryx_refsource_XF
- https://github.com/ellson/graphviz/commit/7aaddf52cd98589fb0c3ab72a393f8411838438a x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2014-0978
- https://security.gentoo.org/glsa/201702-06 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2014-0978
Change history (0)
No recorded changes yet.