#VU18637 NULL pointer dereference in graphviz - CVE-2019-11023
Published: May 29, 2019
graphviz
The Graphviz Project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in the agroot() function within cgraphobj.c of the libcgraph.a. A remote attacker can pass specially crafted GraphML input to the affected application and perform a denial of service (DoS) attack.