PT-2019-5194 · At&T+4 · Graphviz+4

Published

2019-04-02

·

Updated

2024-06-15

·

CVE-2019-11023

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Graphviz versions 2.39.20160612.1140
Description The issue is related to a NULL pointer dereference in the agroot() function, which can be exploited to cause a denial of service. This function is part of the Graphviz application for graph visualization.
Recommendations For Graphviz version 2.39.20160612.1140, consider disabling the agroot() function as a temporary workaround until a patch is available. Restrict access to the cgraph/obj.c module in libcgraph.a to minimize the risk of exploitation. Avoid using the agroot() function in the affected Graphviz version until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01868
CVE-2019-11023
ECHO-0ABA-8609-8043
MGASA-2019-0305
OPENSUSE-SU-2019:1434-1
OPENSUSE-SU-2019:1459-1
OPENSUSE-SU-2019_1434-1
OPENSUSE-SU-2019_1459-1
OPENSUSE-SU-2020:0876-1
OPENSUSE-SU-2020:0906-1
OPENSUSE-SU-2020_0876-1
OPENSUSE-SU-2020_0906-1
OPENSUSE-SU-2024:10821-1
SUSE-SU-2019:1267-1
SUSE-SU-2019:1267-2
SUSE-SU-2019:1267-3
SUSE-SU-2019_1267-1
SUSE-SU-2019_1267-2
SUSE-SU-2019_1267-3
USN-5264-1
USN-5971-1

Affected Products

Debian
Graphviz
Linuxmint
Suse
Ubuntu