PT-2024-4536 · Graphviz+6 · Graphviz+6

Meng Ruijie

·

Published

2024-01-26

·

Updated

2026-03-29

·

CVE-2023-46045

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Graphviz versions 2.36.0 through 9.x before 10.0.1 Graphviz versions 2.36 before 10.0.0
Description: The issue is related to an out-of-bounds read in the Graphviz application, which can be exploited via a crafted config6a file. This may allow an attacker to execute arbitrary code. The exploitability may be uncommon because the config6a file is typically owned by root.
Recommendations: For Graphviz versions 2.36.0 through 9.x before 10.0.1, update to version 10.0.1 or later to resolve the issue. For Graphviz versions 2.36 before 10.0.0, update to version 10.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the config6a file to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3984
AZL-34237
AZL-34768
BDU:2024-05040
CVE-2023-46045
OESA-2024-1209
OPENSUSE-SU-2024:13761-1
OPENSUSE-SU-2024_1351-1
SUSE-SU-2024:1351-1
SUSE-SU-2024:1351-2
SUSE-SU-2024_1351-1
SUSE-SU-2024_1351-2
USN-6708-1

Affected Products

Alt Linux
Debian
Graphviz
Linuxmint
Red Os
Suse
Ubuntu