6.8
CVSSv2

CVE-2019-11023

Published: 08/04/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

graphviz graphviz 2.39.20160612.1140

Vendor Advisories

Debian Bug report logs - #926724 graphviz: CVE-2019-11023 Package: src:graphviz; Maintainer for src:graphviz is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Apr 2019 16:21:02 UTC Severity: normal Tags: security, upstream Found in versions graphviz/24 ...
Several security issues were fixed in graphviz ...
The agroot() function in cgraph\objc in libcgrapha in Graphviz has a NULL pointer dereference, as demonstrated by graphml2gv (CVE-2019-11023) ...
Impact: Moderate Public Date: 2019-04-09 CWE: CWE-476 Bugzilla: 1699848: CVE-2019-11023 graphviz: null ...