Format string error - CVE-2014-9157
Published: December 3, 2014 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Affected software
Fedora
graphviz (Alpine package)
graphviz
How to mitigate CVE-2014-9157
graphviz - update to 2.38.0-11.fc21
External References
- http://advisories.mageia.org/MGASA-2014-0520.html
- http://seclists.org/oss-sec/2014/q4/784
- http://seclists.org/oss-sec/2014/q4/872
- http://secunia.com/advisories/60166
- http://www.debian.org/security/2014/dsa-3098
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:248
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:187
- http://www.securityfocus.com/bid/71283
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98949
- https://github.com/ellson/graphviz/commit/99eda421f7ddc27b14e4ac1d2126e5fe41719081