CVE-2023-46045: High severity graphviz vulnerability
Published Feb 2, 2024
·Updated
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
Affected Software
8 affected componentsFixes available
debian/graphviz
2.42.2-82.42.2-9
ubuntu/graphviz<2.40.1-2ubuntu0.1~
2.40.1-2ubuntu0.1~
ubuntu/graphviz<2.42.2-3ubuntu0.1~
2.42.2-3ubuntu0.1~
ubuntu/graphviz<2.42.2-6ubuntu0.1~
2.42.2-6ubuntu0.1~
ubuntu/graphviz<2.36.0-0ubuntu3.2+
2.36.0-0ubuntu3.2+
ubuntu/graphviz<2.42.2-8
2.42.2-8
ubuntu/graphviz<2.38.0-12ubuntu2.1+
2.38.0-12ubuntu2.1+
Graphviz graphviz>=2.36.0<10.0.0
Event History
Feb 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Mar 30, 2024
Data Sourced
via Launchpad·10:24 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-46045?
CVE-2023-46045 is classified as a moderate severity vulnerability due to its out-of-bounds read, but exploitability may be uncommon.
2
How do I fix CVE-2023-46045?
To fix CVE-2023-46045, update Graphviz to version 10.0.1 or later.
3
Which versions of Graphviz are affected by CVE-2023-46045?
CVE-2023-46045 affects Graphviz versions 2.36.0 through 9.x before 10.0.1.
4
Can CVE-2023-46045 be exploited by regular users?
Exploitability of CVE-2023-46045 may be uncommon because the config6a file is typically owned by root.
5
What type of vulnerability is CVE-2023-46045?
CVE-2023-46045 is an out-of-bounds read vulnerability.