← Back

CVE-2008-4555

nvd nist
Published: Oct 14, 2008Modified: Apr 23, 2026

JSON object

Loading...
8.5
Vector
AV:N/AC:M/Au:S/C:C/I:C/A:C
Exploitability: 6.8 / Impact: 10.0
Source: NVD

Description

Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agraph_t elements.

Affected (40)

Products: Graphviz: Graphviz
1 product
Graphviz
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Graphviz
Up to 2.20.2
Version 1.10_2003-09-15_0415_1
Version 1.10_2003-09-15_0415_2
Version 1.12.1
Version 1.12.2
Version 1.12.3
Version 1.14.1
Version 1.16.1
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.7.16.1
Version 1.7.16.2
Version 1.7.5.1
Version 1.7.5.2
Version 1.7.5.3
Version 1.7.5.4
Version 1.7.5.5
Version 1.7.5.6
Version 1.7.5.7
Version 1.7.5_0.1
Version 1.7.5_0.2
Version 1.7.5_0.3
Version 1.8.5.1
Version 1.8.5.2
Version 1.8.9.1
Version 2.10
Version 2.12
Version 2.14
Version 2.16
Version 2.18
Version 2.2.1.1
Version 2.2.1
Version 2.2.2
Version 2.20.0
Version 2.20.1
Version 2.2
Version 2.4
Version 2.6
Version 2.8

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.