CVE-2014-9157Use of Externally-Controlled Format String in Graphviz

Severity
7.5HIGHNVD
EPSS
1.9%
top 16.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3
Latest updateMay 17

Description

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/graphviz< graphviz 2.38.0-7 (bookworm)
NVDgraphviz/graphviz< 2.42.4
Debiangraphviz/graphviz< 2.38.0-7+3

Also affects: Debian Linux 7.0, 8.0

🔴Vulnerability Details

2
GHSA
GHSA-h5f2-wwmp-f73m: Format string vulnerability in the yyerror function in lib/cgraph/scan2022-05-17
OSV
CVE-2014-9157: Format string vulnerability in the yyerror function in lib/cgraph/scan2014-12-03

📋Vendor Advisories

3
Ubuntu
Graphviz vulnerability2014-12-09
Red Hat
graphviz: format string vulnerability in yyerror()2014-11-25
Debian
CVE-2014-9157: graphviz - Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Grap...2014

💬Community

1
Bugzilla
CVE-2014-9157 graphviz: format string vulnerability in yyerror()2014-11-25