VulnerabilityModified
CVE-2019-9904
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.
MEDIUM 6.5EPSS 2.70%
Does this matter?
Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 2.70% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-674
- Affected
- graphviz/graphviz
- Source
- cve@mitre.org
References
- https://gitlab.com/graphviz/graphviz/issues/1512Exploit, Issue Tracking, Third Party Advisory
- https://research.loginsoft.com/bugs/stack-buffer-overflow-in-function-agclose-graphviz/Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/202107-04Third Party Advisory
- https://gitlab.com/graphviz/graphviz/issues/1512Exploit, Issue Tracking, Third Party Advisory
- https://research.loginsoft.com/bugs/stack-buffer-overflow-in-function-agclose-graphviz/Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/202107-04Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.