CVE-2014-1235: Buffer Overflow
Graphviz, a collection of tools for the manipulation and layout of graphs, was recently reported to be affected by a buffer overflow vulnerability, which seem to have introduced in the fix for CVE-2014-0978.
References: http://seclists.org/oss-sec/2014/q1/46
Commit: https://github.com/ellson/graphviz/commit/d266bb2b4154d11c27252b56d86963aef4434750
Other sources
Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-0978.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1235?
CVE-2014-1235 is classified as a high-severity buffer overflow vulnerability affecting Graphviz.
How do I fix CVE-2014-1235?
To mitigate CVE-2014-1235, upgrade Graphviz to version 2.34.1 or later.
What versions of Graphviz are affected by CVE-2014-1235?
Graphviz version 2.34.0 is specifically affected by CVE-2014-1235.
What type of vulnerability is CVE-2014-1235?
CVE-2014-1235 is a buffer overflow vulnerability that can lead to execution of arbitrary code.
Is there a workaround for CVE-2014-1235?
There are no known effective workarounds for CVE-2014-1235 other than applying the available security updates.