SB2014112506 - Fedora 21 update for graphviz
Published: November 25, 2014 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Format string error (CVE-ID: CVE-2014-9157)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Remediation
Install update from vendor's website.