Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Mageia 7, 8: MGASA-2021-0228 Severe: Graphviz Remote Code Execution

mageia
Calendar Grey June 8, 2021
Dist Mageia Esm H88
The advisory issued by Mageia on 2021-0228 highlights a critical vulnerability in Graphviz that could enable remote code execution or lead to system crashes.
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (applicatio...

Summary

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component. (CVE-2020-18032)

References

- https://bugs.mageia.org/show_bug.cgi?id=28989

- https://lists.debian.org/debian-security-announce/2021/msg00095.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/D5PQPHJHPU46FK3R5XBP3XDT4X37HMPC/

-

- https://www.cve.org/CVERecord?id=CVE-2020-18032

Resolution

SRPMS

- 8/core/graphviz-2.44.1-2.1.mga8

- 7/core/graphviz-2.40.1-17.2.mga7

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0228.html
Type: security
CVE: CVE-2020-18032

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here