The updated packages fix a security vulnerability:
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz
2.39.20160612.1140 has a NULL pointer dereference, as demonstrated
by graphml2gv. (CVE-2019-11023)
- https://bugs.mageia.org/show_bug.cgi?id=25563
- https://bugzilla.redhat.com/show_bug.cgi?id=1699848
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI3D5TQE3IMCSF5OUTXQL4GVKFCIY5JG/
- https://www.cve.org/CVERecord?id=CVE-2019-11023
- 7/core/graphviz-2.40.1-17.1.mga7
Get the latest Linux and open source security news straight to your inbox.