MGASA-2019-0305

Source
https://advisories.mageia.org/MGASA-2019-0305.html
Import Source
https://advisories.mageia.org/MGASA-2019-0305.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0305
Related
Published
2019-10-29T14:54:30Z
Modified
2019-10-29T14:36:32Z
Summary
Updated graphviz packages fix security vulnerability
Details

The updated packages fix a security vulnerability:

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. (CVE-2019-11023)

References
Credits

Affected packages

Mageia:7 / graphviz

Package

Name
graphviz
Purl
pkg:rpm/mageia/graphviz?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.40.1-17.1.mga7

Ecosystem specific

{
    "section": "core"
}