PT-2024-4536 · Graphviz+6 · Graphviz+6
Meng Ruijie
·
Published
2024-01-26
·
Updated
2026-03-29
·
CVE-2023-46045
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Graphviz versions 2.36.0 through 9.x before 10.0.1
Graphviz versions 2.36 before 10.0.0
Description:
The issue is related to an out-of-bounds read in the Graphviz application, which can be exploited via a crafted config6a file. This may allow an attacker to execute arbitrary code. The exploitability may be uncommon because the config6a file is typically owned by root.
Recommendations:
For Graphviz versions 2.36.0 through 9.x before 10.0.1, update to version 10.0.1 or later to resolve the issue.
For Graphviz versions 2.36 before 10.0.0, update to version 10.0.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the config6a file to minimize the risk of exploitation.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Graphviz
Linuxmint
Red Os
Suse
Ubuntu