First published: Mon Apr 08 2019(Updated: )
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Graphviz Graphviz | =2.39.20160612.1140 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11023 has a medium severity rating due to the potential for a NULL pointer dereference leading to application crashes.
To fix CVE-2019-11023, update Graphviz to a version that addresses this vulnerability.
CVE-2019-11023 specifically affects Graphviz version 2.39.20160612.1140.
The vulnerability in CVE-2019-11023 involves a NULL pointer dereference in the agroot() function of libcgraph.a.
CVE-2019-11023 requires local access to exploit the NULL pointer dereference, generally via crafted GraphML files.