ArchLinux: 201412-4: graphviz: format string vulnerability
Summary
A format string vulnerability has been found in the error reporting part of the parser used by graphviz.
Resolution
Upgrade to 2.38.0-3.
# pacman -Syu "graphviz>=2.38.0-3"
The problem has been fixed upstream, but there has been no release
including the fix yet.
References
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9157 https://seclists.org/oss-sec/2014/q4/872 https://bugs.archlinux.org/task/42983 https://github.com/ellson/MOTHBALLED-graphviz/commit/99eda421f7ddc27b14e4ac1d2126e5fe41719081
Workaround
None.