First published: Thu May 17 2018(Updated: )
A NULL pointer dereference vulnerability was found in graphviz in the rebuild_vlists function. A maliciously crafted file could cause the application to crash. References: <a href="https://issuetracker.google.com/issues/77810342">https://issuetracker.google.com/issues/77810342</a> Upstream issue: <a href="https://gitlab.com/graphviz/graphviz/issues/1367">https://gitlab.com/graphviz/graphviz/issues/1367</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Graphviz |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1579254 is considered to be high due to the potential for application crashes from a NULL pointer dereference.
To fix REDHAT-BUG-1579254, you should update to the latest version of Graphviz where the vulnerability has been addressed.
All versions of Graphviz prior to the fix release are affected by REDHAT-BUG-1579254.
REDHAT-BUG-1579254 is classified as a NULL pointer dereference vulnerability.
Yes, REDHAT-BUG-1579254 can be exploited remotely through a maliciously crafted file.