VYPR

rpm package

opensuse/graphviz&distro=openSUSE Leap 15.2

pkg:rpm/opensuse/graphviz&distro=openSUSE%20Leap%2015.2

Vulnerabilities (3)

  • CVE-2020-18032Apr 29, 2021
    affected < 2.40.1-lp152.7.10.1fixed 2.40.1-lp152.7.10.1

    Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.

  • CVE-2019-11023Apr 8, 2019
    affected < 2.40.1-lp152.7.2.1fixed 2.40.1-lp152.7.2.1

    The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

  • CVE-2018-10196May 30, 2018
    affected < 2.40.1-lp152.7.7.1fixed 2.40.1-lp152.7.7.1

    NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.