CVE-2020-18032
published 2021-04-29CVE-2020-18032: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.61%
83.9th percentile
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | graphviz | < graphviz 2.42.2-5 (bookworm) | graphviz 2.42.2-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| graphviz | graphviz | < 2.46.0 | 2.46.0 |
| graphviz | graphviz | >= 0 < 2.42.2-5 | 2.42.2-5 |
| graphviz | graphviz | >= 0 < 2.42.2-5 | 2.42.2-5 |
| graphviz | graphviz | >= 0 < 2.42.2-5 | 2.42.2-5 |
| graphviz | graphviz | >= 0 < 2.42.2-5 | 2.42.2-5 |
| graphviz | graphviz | >= 0 < 2.36.0-0ubuntu3.2+esm1 | 2.36.0-0ubuntu3.2+esm1 |
| graphviz | graphviz | >= 0 < 2.38.0-12ubuntu2.1+esm1 | 2.38.0-12ubuntu2.1+esm1 |
| graphviz | graphviz | >= 0 < 2.40.1-2ubuntu0.1~esm1 | 2.40.1-2ubuntu0.1~esm1 |
| graphviz | graphviz | >= 0 < 2.42.2-3ubuntu0.1~esm1 | 2.42.2-3ubuntu0.1~esm1 |
| msrc | azl3_graphviz_2.42.4-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_graphviz_2.42.4-12_on_azure_linux_3.0 | — | — |
| msrc | cbl2_graphviz_2.42.4-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_graphviz_2.42.4-5_on_cbl_mariner_1.0 | — | — |
| msrc | graphviz-2.42.4-11.azl3.aarch64.rpm | — | — |
| msrc | graphviz-2.42.4-11.azl3.x86_64.rpm | — | — |
| msrc | graphviz-2.42.4-5.cm1.aarch64.rpm | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
graphviz vulnerabilities
osv·2023-03-24·CVSS 5.5
CVE-2018-10196 [MEDIUM] graphviz vulnerabilities
graphviz vulnerabilities
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file can cause
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10196)
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file can cause
a denial of service. These issues only affected Ubuntu 14.04 ESM and Ubuntu
18.04 LTS. (CVE-2019-11023)
It was discovered that graphviz contains a buffer overflow vulnerability.
Exploitation via a specially crafted input file can cause a denial of
service or possibly allow for arbitrary code execution. These issues only
affected Ubuntu 14.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-18032)
GHSA
GHSA-92qh-4rf3-8x2m: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a
ghsa_unreviewed·2022-05-24
CVE-2020-18032 [CRITICAL] CWE-120 GHSA-92qh-4rf3-8x2m: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
OSV
graphviz vulnerabilities
osv·2022-02-03·CVSS 5.5
CVE-2018-10196 [MEDIUM] graphviz vulnerabilities
graphviz vulnerabilities
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file
can cause a denial of service.
(CVE-2018-10196, CVE-2019-11023)
It was discovered that graphviz contains a buffer overflow
vulnerability. Exploitation via a specially crafted input file can cause
a denial of service or possibly allow for arbitrary code execution.
(CVE-2020-18032)
OSV
CVE-2020-18032: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a
osv·2021-04-29·CVSS 7.8
CVE-2020-18032 [HIGH] CVE-2020-18032: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Ubuntu
Graphviz vulnerabilities
vendor_ubuntu·2023-03-24·CVSS 5.5
CVE-2019-11023 [MEDIUM] Graphviz vulnerabilities
Title: Graphviz vulnerabilities
Summary: Several security issues were fixed in graphviz.
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file can cause
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10196)
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file can cause
a denial of service. These issues only affected Ubuntu 14.04 ESM and Ubuntu
18.04 LTS. (CVE-2019-11023)
It was discovered that graphviz contains a buffer overflow vulnerability.
Exploitation via a specially crafted input file can cause a denial of
service or possibly allow for arbitrary code execution. These issues only
affected Ubuntu 14.04
Ubuntu
Graphviz vulnerabilities
vendor_ubuntu·2022-02-03·CVSS 5.5
CVE-2018-10196 [MEDIUM] Graphviz vulnerabilities
Title: Graphviz vulnerabilities
Summary: Several security issues were fixed in graphviz.
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file
can cause a denial of service.
(CVE-2018-10196, CVE-2019-11023)
It was discovered that graphviz contains a buffer overflow
vulnerability. Exploitation via a specially crafted input file can cause
a denial of service or possibly allow for arbitrary code execution.
(CVE-2020-18032)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c
vendor_redhat·2021-05-26·CVSS 7.8
CVE-2020-18032 [HIGH] CWE-193 graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c
graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
A flaw was found in graphviz. A wrong assumption in record_init function leads to an off-by-one write in parse_reclbl function, allowing an attacker who can provide graph input to potentially execute code when the label of a node is invalid and shorter than two characters. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: graphviz (Red Hat Enterprise Linux 6) - Out of support scope
Package: graphviz
Microsoft
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading
vendor_msrc·2021-04-13·CVSS 7.8
CVE-2020-18032 [HIGH] CWE-120 Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact
Debian
CVE-2020-18032: graphviz - Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 an...
vendor_debian·2020·CVSS 7.8
CVE-2020-18032 [HIGH] CVE-2020-18032: graphviz - Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 an...
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Scope: local
bookworm: resolved (fixed in 2.42.2-5)
bullseye: resolved (fixed in 2.42.2-5)
forky: resolved (fixed in 2.42.2-5)
sid: resolved (fixed in 2.42.2-5)
trixie: resolved (fixed in 2.42.2-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/graphviz/graphviz/-/issues/1700https://lists.debian.org/debian-lts-announce/2021/05/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5PQPHJHPU46FK3R5XBP3XDT4X37HMPC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGY2IGARE6RZHTF2UEZEWLMQCDILFK6A/https://security.gentoo.org/glsa/202107-04https://www.debian.org/security/2021/dsa-4914https://gitlab.com/graphviz/graphviz/-/issues/1700https://lists.debian.org/debian-lts-announce/2021/05/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5PQPHJHPU46FK3R5XBP3XDT4X37HMPC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGY2IGARE6RZHTF2UEZEWLMQCDILFK6A/https://security.gentoo.org/glsa/202107-04https://www.debian.org/security/2021/dsa-4914
2021-04-29
Published