CVE-2020-18032
29.04.2021, 18:15
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| graphviz | graphviz | 𝑥 < 2.46.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| graphviz |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| graphviz |
| ||||||||||||||||||||||||||||||||||
| graphviz-devel |
| ||||||||||||||||||||||||||||||||||
| graphviz-gd |
| ||||||||||||||||||||||||||||||||||
| graphviz-gnome |
| ||||||||||||||||||||||||||||||||||
| graphviz-perl |
| ||||||||||||||||||||||||||||||||||
| graphviz-plugins-core |
| ||||||||||||||||||||||||||||||||||
| graphviz-tcl |
| ||||||||||||||||||||||||||||||||||
| libgraphviz6 |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| graphviz |
| ||
| graphviz-R |
| ||
| graphviz-debuginfo |
| ||
| graphviz-devel |
| ||
| graphviz-doc |
| ||
| graphviz-gd |
| ||
| graphviz-graphs |
| ||
| graphviz-guile |
| ||
| graphviz-java |
| ||
| graphviz-lua |
| ||
| graphviz-perl |
| ||
| graphviz-php54 |
| ||
| graphviz-python26 |
| ||
| graphviz-python27 |
| ||
| graphviz-ruby |
| ||
| graphviz-tcl |
|
Azure Linux Releases
References