SB2021070605 - Gentoo update for Graphviz
Published: July 6, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2019-9904)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in libcdtdttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in libcgraphgraph.c in libcgraph.a, related to agfstsubg in libcgraphsubg.c.
2) Heap-based buffer overflow (CVE-ID: CVE-2020-18032)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in lib/common/shapes.c. A remote attacker can pass specially crafted data to the application, trigger heap-based buffer overflow and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.