Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-18032

Опубликовано: 26 мая 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.

A flaw was found in graphviz. A wrong assumption in record_init function leads to an off-by-one write in parse_reclbl function, allowing an attacker who can provide graph input to potentially execute code when the label of a node is invalid and shorter than two characters. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6graphvizOut of support scope
Red Hat Enterprise Linux 7graphvizOut of support scope
Red Hat Enterprise Linux 9graphvizNot affected
Red Hat Enterprise Linux 8graphvizFixedRHSA-2021:425609.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1966272graphviz: off-by-one in parse_reclbl() in lib/common/shapes.c

EPSS

Процентиль: 64%
0.00469
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.

CVSS3: 7.8
nvd
больше 4 лет назад

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.

CVSS3: 7.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.8
debian
больше 4 лет назад

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f ...

suse-cvrf
около 4 лет назад

Security update for graphviz

EPSS

Процентиль: 64%
0.00469
Низкий

7.8 High

CVSS3