Advisories ยป MGASA-2019-0305

Updated graphviz packages fix security vulnerability

Publication date: 29 Oct 2019
Modification date: 29 Oct 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-11023

Description

The updated packages fix a security vulnerability:

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 
2.39.20160612.1140 has a NULL pointer dereference, as demonstrated
by graphml2gv. (CVE-2019-11023)
                

References

SRPMS

7/core