Vulnerabilities > CVE-2019-11023 - NULL Pointer Dereference vulnerability in Graphviz 2.39.20160612.1140

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
graphviz
CWE-476
nessus

Summary

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

Vulnerable Configurations

Part Description Count
Application
Graphviz
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyHuawei Local Security Checks
    NASL idEULEROS_SA-2019-1677.NASL
    descriptionAccording to the version of the graphviz packages installed, the EulerOS installation on the remote host is affected by the following vulnerability : - The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.(CVE-2019-11023) Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-05-06
    modified2019-07-02
    plugin id126419
    published2019-07-02
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126419
    titleEulerOS 2.0 SP5 : graphviz (EulerOS-SA-2019-1677)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2019-1459.NASL
    descriptionThis update for graphviz fixes the following issues : Security issue fixed : - CVE-2019-11023: Fixed a denial of service vulnerability, which was caused by a NULL pointer dereference in agroot() (bsc#1132091). This update was imported from the SUSE:SLE-15:Update update project.
    last seen2020-06-01
    modified2020-06-02
    plugin id125532
    published2019-05-29
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125532
    titleopenSUSE Security Update : graphviz (openSUSE-2019-1459)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2019-1267-1.NASL
    descriptionThis update for graphviz fixes the following issues : Security issue fixed : CVE-2019-11023: Fixed a denial of service vulnerability, which was caused by a NULL pointer dereference in agroot() (bsc#1132091). Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id125246
    published2019-05-17
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125246
    titleSUSE SLED15 / SLES15 Security Update : graphviz (SUSE-SU-2019:1267-1)
  • NASL familyAmazon Linux Local Security Checks
    NASL idALA_ALAS-2019-1207.NASL
    descriptionThe agroot() function in cgraph\obj.c in libcgraph.a in Graphviz has a NULL pointer dereference, as demonstrated by graphml2gv. (CVE-2019-11023)
    last seen2020-06-01
    modified2020-06-02
    plugin id125293
    published2019-05-21
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125293
    titleAmazon Linux AMI : graphviz (ALAS-2019-1207)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2019-FEEB1A2543.NASL
    descriptionThis is an update fixing CVE-2019-11023. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id125345
    published2019-05-23
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125345
    titleFedora 29 : graphviz (2019-feeb1a2543)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2019-1434.NASL
    descriptionThis update for graphviz fixes the following issues : Security issue fixed : - CVE-2019-11023: Fixed a denial of service vulnerability, which was caused by a NULL pointer dereference in agroot() (bsc#1132091). This update was imported from the SUSE:SLE-15:Update update project.
    last seen2020-06-01
    modified2020-06-02
    plugin id125349
    published2019-05-23
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125349
    titleopenSUSE Security Update : graphviz (openSUSE-2019-1434)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2019-521E6C567C.NASL
    descriptionThis is an update fixing CVE-2019-11023. ---- Fixed NULL pointer dereference in function agroot(), CVE-2019-11023 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id124601
    published2019-05-06
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/124601
    titleFedora 30 : graphviz (2019-521e6c567c)
  • NASL familyHuawei Local Security Checks
    NASL idEULEROS_SA-2019-1760.NASL
    descriptionAccording to the version of the graphviz packages installed, the EulerOS installation on the remote host is affected by the following vulnerability : - The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.(CVE-2019-11023) Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-05-03
    modified2019-07-25
    plugin id126997
    published2019-07-25
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126997
    titleEulerOS 2.0 SP8 : graphviz (EulerOS-SA-2019-1760)
  • NASL familyHuawei Local Security Checks
    NASL idEULEROS_SA-2019-2064.NASL
    descriptionAccording to the version of the graphviz packages installed, the EulerOS installation on the remote host is affected by the following vulnerability : - The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.(CVE-2019-11023) Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-05-08
    modified2019-09-24
    plugin id129257
    published2019-09-24
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/129257
    titleEulerOS 2.0 SP3 : graphviz (EulerOS-SA-2019-2064)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2019-1267-2.NASL
    descriptionThis update for graphviz fixes the following issues : Security issue fixed : CVE-2019-11023: Fixed a denial of service vulnerability, which was caused by a NULL pointer dereference in agroot() (bsc#1132091). Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id126458
    published2019-07-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126458
    titleSUSE SLED15 / SLES15 Security Update : graphviz (SUSE-SU-2019:1267-2)
  • NASL familyHuawei Local Security Checks
    NASL idEULEROS_SA-2019-1726.NASL
    descriptionAccording to the version of the graphviz packages installed, the EulerOS installation on the remote host is affected by the following vulnerability : - The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.(CVE-2019-11023) Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-05-06
    modified2019-07-22
    plugin id126853
    published2019-07-22
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126853
    titleEulerOS 2.0 SP2 : graphviz (EulerOS-SA-2019-1726)