CVE-2019-9904: Medium severity graphviz vulnerability
Published Mar 21, 2019
·Updated
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.
Affected Software
1 affected component
Graphviz graphviz=2.40.1
Event History
Mar 21, 2019
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9904?
CVE-2019-9904 is classified as a medium severity vulnerability due to its stack consumption risk.
2
How do I fix CVE-2019-9904?
To fix CVE-2019-9904, update Graphviz to a version newer than 2.40.1 that addresses this vulnerability.
3
What type of vulnerability is CVE-2019-9904?
CVE-2019-9904 is a stack consumption vulnerability caused by recursive calls in graph rendering.
4
Which version of Graphviz is affected by CVE-2019-9904?
Graphviz version 2.40.1 is affected by CVE-2019-9904.
5
How can CVE-2019-9904 impact my system?
CVE-2019-9904 can lead to denial of service due to stack exhaustion on systems running the affected version.