SB2015012709 - Format string error in graphviz (Alpine package)
Published: January 27, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Format string error (CVE-ID: CVE-2014-9157)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Remediation
Install update from vendor's website.