CVE-2014-9157
published 2014-12-03CVE-2014-9157: Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.57%
92.0th percentile
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | graphviz | < graphviz 2.38.0-7 (bookworm) | graphviz 2.38.0-7 (bookworm) |
| graphviz | graphviz | < 2.42.4 | 2.42.4 |
| graphviz | graphviz | >= 0 < 2.38.0-7 | 2.38.0-7 |
| graphviz | graphviz | >= 0 < 2.38.0-7 | 2.38.0-7 |
| graphviz | graphviz | >= 0 < 2.38.0-7 | 2.38.0-7 |
| graphviz | graphviz | >= 0 < 2.38.0-7 | 2.38.0-7 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Graphviz vulnerability
vendor_ubuntu·2014-12-09
CVE-2014-9157 Graphviz vulnerability
Title: Graphviz vulnerability
Summary: graphviz could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that graphviz incorrectly handled parsing errors. An
attacker could use this issue to cause graphviz to crash or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
graphviz: format string vulnerability in yyerror()
vendor_redhat·2014-11-25·CVSS 7.5
CVE-2014-9157 [HIGH] CWE-134 graphviz: format string vulnerability in yyerror()
graphviz: format string vulnerability in yyerror()
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Statement: This issue affects the versions of the graphviz package as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this issue as having Low security impact and therefore it is not planned to be addressed in future updates.
Package: graphviz (Red Hat Enterprise Linux 6) - Will not fix
Package: graphviz (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9157: graphviz - Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Grap...
vendor_debian·2014·CVSS 7.5
CVE-2014-9157 [HIGH] CVE-2014-9157: graphviz - Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Grap...
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Scope: local
bookworm: resolved (fixed in 2.38.0-7)
bullseye: resolved (fixed in 2.38.0-7)
forky: resolved (fixed in 2.38.0-7)
sid: resolved (fixed in 2.38.0-7)
trixie: resolved (fixed in 2.38.0-7)
GHSA
GHSA-h5f2-wwmp-f73m: Format string vulnerability in the yyerror function in lib/cgraph/scan
ghsa_unreviewed·2022-05-17
CVE-2014-9157 [HIGH] CWE-134 GHSA-h5f2-wwmp-f73m: Format string vulnerability in the yyerror function in lib/cgraph/scan
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
OSV
CVE-2014-9157: Format string vulnerability in the yyerror function in lib/cgraph/scan
osv·2014-12-03·CVSS 7.5
CVE-2014-9157 [HIGH] CVE-2014-9157: Format string vulnerability in the yyerror function in lib/cgraph/scan
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0520.htmlhttp://seclists.org/oss-sec/2014/q4/784http://seclists.org/oss-sec/2014/q4/872http://secunia.com/advisories/60166http://www.debian.org/security/2014/dsa-3098http://www.mandriva.com/security/advisories?name=MDVSA-2014:248http://www.mandriva.com/security/advisories?name=MDVSA-2015:187http://www.securityfocus.com/bid/71283https://exchange.xforce.ibmcloud.com/vulnerabilities/98949https://github.com/ellson/graphviz/commit/99eda421f7ddc27b14e4ac1d2126e5fe41719081http://advisories.mageia.org/MGASA-2014-0520.htmlhttp://seclists.org/oss-sec/2014/q4/784http://seclists.org/oss-sec/2014/q4/872http://secunia.com/advisories/60166http://www.debian.org/security/2014/dsa-3098http://www.mandriva.com/security/advisories?name=MDVSA-2014:248http://www.mandriva.com/security/advisories?name=MDVSA-2015:187http://www.securityfocus.com/bid/71283https://exchange.xforce.ibmcloud.com/vulnerabilities/98949https://github.com/ellson/graphviz/commit/99eda421f7ddc27b14e4ac1d2126e5fe41719081
2014-12-03
Published