Updated graphviz packages fix security vulnerability
Publication date: 29 Oct 2019Modification date: 29 Oct 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-11023
Description
The updated packages fix a security vulnerability: The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. (CVE-2019-11023)
References
SRPMS
7/core
- graphviz-2.40.1-17.1.mga7