CVE-2008-4555: Buffer Overflow
Stack-based buffer overflow in the pushsubg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agrapht elements.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4555?
CVE-2008-4555 has been classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2008-4555?
To fix CVE-2008-4555, you should upgrade to the latest version of Graphviz that is not affected by this vulnerability.
What versions of Graphviz are affected by CVE-2008-4555?
CVE-2008-4555 affects Graphviz versions up to and including 2.20.2 and possibly earlier versions.
What type of vulnerability is CVE-2008-4555?
CVE-2008-4555 is a stack-based buffer overflow vulnerability in the push_subg function of the Graphviz parsing process.
Can CVE-2008-4555 result in a denial of service?
Yes, CVE-2008-4555 can cause a denial of service through memory corruption triggered by specially crafted DOT files.