CVE-2014-9157: High severity debian linux vulnerability
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9157?
CVE-2014-9157 has a medium severity rating due to the potential for remote attackers to exploit the vulnerability.
How do I fix CVE-2014-9157?
To fix CVE-2014-9157, upgrade to a patched version of Graphviz that addresses the format string vulnerability.
What are the affected versions for CVE-2014-9157?
CVE-2014-9157 affects Graphviz versions up to but not including 2.42.4, as well as specific Debian Linux releases 7.0 and 8.0.
What is the impact of exploiting CVE-2014-9157?
Exploiting CVE-2014-9157 may allow remote attackers to cause unspecified effects through unhandled format string specifiers.
Is CVE-2014-9157 still a concern today?
CVE-2014-9157 may still be a concern for systems running affected versions of Graphviz or the specified Debian releases that have not been updated.