Описание
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-9157
- https://github.com/ellson/graphviz/commit/99eda421f7ddc27b14e4ac1d2126e5fe41719081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98949
- http://advisories.mageia.org/MGASA-2014-0520.html
- http://seclists.org/oss-sec/2014/q4/784
- http://seclists.org/oss-sec/2014/q4/872
- http://secunia.com/advisories/60166
- http://www.debian.org/security/2014/dsa-3098
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:248
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:187
- http://www.securityfocus.com/bid/71283
Связанные уязвимости
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
Format string vulnerability in the yyerror function in lib/cgraph/scan ...