7.5
CVSSv2

CVE-2014-9157

Published: 03/12/2014 Updated: 08/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote malicious users to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 7.0

graphviz graphviz -

Vendor Advisories

Debian Bug report logs - #772648 graphviz: format string vulnerability (CVE-2014-9157) Package: graphviz; Maintainer for graphviz is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for graphviz is src:graphviz (PTS, buildd, popcon) Reported by: Marc Deslauriers <marcdeslauriers@ubuntucom> Date: Tue, 9 Dec 2014 1 ...
graphviz could be made to crash or run programs if it opened a specially crafted file ...
Joshua Rogers discovered a format string vulnerability in the yyerror function in lib/cgraph/scanl in Graphviz, a rich set of graph drawing tools An attacker could use this flaw to cause graphviz to crash or possibly execute arbitrary code For the stable distribution (wheezy), this problem has been fixed in version 2263-14+deb7u2 For the upco ...
Format string vulnerability in the yyerror function in lib/cgraph/scanl in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vector, which are not properly handled in an error string ...
Format string vulnerability in the yyerror function in lib/cgraph/scanl in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vector, which are not properly handled in an error string ...