Mageia 2019-0305: graphviz security update
Summary
The updated packages fix a security vulnerability:
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz
2.39.20160612.1140 has a NULL pointer dereference, as demonstrated
by graphml2gv. (CVE-2019-11023)
References
- https://bugs.mageia.org/show_bug.cgi?id=25563
- https://bugzilla.redhat.com/show_bug.cgi?id=1699848
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI3D5TQE3IMCSF5OUTXQL4GVKFCIY5JG/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11023
Resolution
MGASA-2019-0305 - Updated graphviz packages fix security vulnerability
SRPMS
- 7/core/graphviz-2.40.1-17.1.mga7