Format string error - CVE-2014-9157

 

Format string error - CVE-2014-9157

Published: December 3, 2014 / Updated: August 3, 2020


Vulnerability identifier: #VU33058
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9157
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.


Affected software

Amazon Linux AMI
Fedora
graphviz (Alpine package)
graphviz

How to mitigate CVE-2014-9157

Install update from vendor's website.

graphviz (Alpine package) - addressed in versions 2.38.0-r2, 2.38.0-r6, 2.40.1-r0
graphviz - update to 2.38.0-11.fc21

External References

Related Security Bulletins