CVE-2019-9904

A

n issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.

Configurations

Configuration 1 (hide)

cpe:2.3:a:graphviz:graphviz:2.40.1:*:*:*:*:*:*:*

History

21 Nov 2024, 04:52

Type Values Removed Values Added
References () https://gitlab.com/graphviz/graphviz/issues/1512 - Exploit, Issue Tracking, Third Party Advisory () https://gitlab.com/graphviz/graphviz/issues/1512 - Exploit, Issue Tracking, Third Party Advisory
References () https://research.loginsoft.com/bugs/stack-buffer-overflow-in-function-agclose-graphviz/ - Exploit, Third Party Advisory () https://research.loginsoft.com/bugs/stack-buffer-overflow-in-function-agclose-graphviz/ - Exploit, Third Party Advisory
References () https://security.gentoo.org/glsa/202107-04 - Third Party Advisory () https://security.gentoo.org/glsa/202107-04 - Third Party Advisory

Information

Published : 2019-03-21 18:29

Updated : 2024-11-21 04:52


NVD link : CVE-2019-9904

Mitre link : CVE-2019-9904

CVE.ORG link : CVE-2019-9904


JSON object : View

Products Affected
CWE
CWE-674

Uncontrolled Recursion