CVE-2019-11023: Null Pointer Dereference
Published Apr 8, 2019
·Updated
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.
Affected Software
1 affected component
Graphviz graphviz=2.39.20160612.1140
Event History
Apr 8, 2019
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11023?
CVE-2019-11023 has a medium severity rating due to the potential for a NULL pointer dereference leading to application crashes.
2
How do I fix CVE-2019-11023?
To fix CVE-2019-11023, update Graphviz to a version that addresses this vulnerability.
3
What software is affected by CVE-2019-11023?
CVE-2019-11023 specifically affects Graphviz version 2.39.20160612.1140.
4
What is the nature of the vulnerability in CVE-2019-11023?
The vulnerability in CVE-2019-11023 involves a NULL pointer dereference in the agroot() function of libcgraph.a.
5
Can CVE-2019-11023 be exploited remotely?
CVE-2019-11023 requires local access to exploit the NULL pointer dereference, generally via crafted GraphML files.