Updated graphviz packages fix security vulnerability
Publication date: 29 Oct 2019Modification date: 29 Oct 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-11023
Description
The updated packages fix a security vulnerability:
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz
2.39.20160612.1140 has a NULL pointer dereference, as demonstrated
by graphml2gv. (CVE-2019-11023)
References
SRPMS
7/core
- graphviz-2.40.1-17.1.mga7