Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
References
Information
Published : 2014-12-03 13:59
Updated : 2017-09-07 18:29
NVD link : CVE-2014-9157
Mitre link : CVE-2014-9157
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
debian
- debian_linux
graphviz
- graphviz