QID 357246
Date Published: 2024-02-20
QID 357246: Amazon Linux Security Advisory for graphviz : ALAS2023-2024-527
Buffer overflow via a crafted config6a file note: crosses no security boundary, config files are under local control note: https://gitlab.com/graphviz/graphviz/-/issues/2441 note: introduced by: https://gitlab.com/graphviz/graphviz/-/commit/cf95714837f06f684929b54659523c2c9b1fc19f (2.38.0) note: fixed by: https://gitlab.com/graphviz/graphviz/-/commit/361f274ca901c3c476697a6404662d95f4dd43cb note: fixed by: https://gitlab.com/graphviz/graphviz/-/commit/3f31704cafd7da3e86bb2861accf5e90c973e62a note: fixed by: https://gitlab.com/graphviz/graphviz/-/commit/a95f977f5d809915ec4b14836d2b5b7f5e74881e (cve-2023-46045)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2023-2024-527 -
alas.aws.amazon.com/AL2023/ALAS-2024-527.html
CVEs related to QID 357246
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2024-527 | amazon linux 2023 |
|