Novell Home

CVE-2008-4555

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-4555 at MITRE

Description

Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agraph_t elements.

Novell/SUSE information

Novell Bugzilla entry: 433747

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Novell Linux Desktop 9 SDK for x86
Novell Linux Desktop 9 SDK for x86_64
SLES SDK 9 for IBM S/390 and IBM zSeries
SLES SDK 9 for IBM iSeries and IBM pSeries
SLES SDK 9 for IBM zSeries
SLES SDK 9 for IPF
SLES SDK 9 for X86-64
SLES SDK 9 for x86
  • graphviz >= 1.11-34.4
  • graphviz-devel >= 1.11-34.4
  • graphviz-graphs >= 1.11-34.4
  • graphviz-tcl >= 1.11-34.4
core9.s390
core9.x86
core9.x86-64
core9.ppc
sles9-nld.x86
core9.s390x
core9.ia64
sles9-nld.x86-64
YOU Patch Nr: 12270
openSUSE 10.2
  • graphviz >= 2.6-46
  • graphviz-devel >= 2.6-46
  • graphviz-tcl >= 2.6-46
openSUSE 10.3
  • graphviz >= 2.12-50.2
  • graphviz-devel >= 2.12-50.2
  • graphviz-doc >= 2.12-50.2
  • graphviz-gd >= 2.12-50.2
  • graphviz-guile >= 2.12-50.2
  • graphviz-java >= 2.12-50.2
  • graphviz-lua >= 2.12-50.2
  • graphviz-ocaml >= 2.12-50.2
  • graphviz-perl >= 2.12-50.2
  • graphviz-php >= 2.12-50.2
  • graphviz-python >= 2.12-50.2
  • graphviz-ruby >= 2.12-50.2
  • graphviz-sharp >= 2.12-50.2
  • graphviz-tcl >= 2.12-50.2
SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP1 for x86
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP2 for x86
  • graphviz >= 2.6-22.6
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sle10-sp2-sdk.ppc
sle10-sp2-sdk.s390x
sle10-sp1-sdk.ia64
sle10-sp1-sdk.x86
sle10-sp1-sdk.ppc
sled10.x86
sle10-sp2-sdk.x86
sled10-sp2.x86
sle10-sp2-sdk.ia64
sled10-sp2.x86-64
sled10.x86-64
sle10-sp2-sdk.x86-64
ZYPP Patch Nr: 5688
SLE SDK 10 SP1 for IBM iSeries and IBM pSeries
SLE SDK 10 SP1 for IBM zSeries
SLE SDK 10 SP1 for IPF
SLE SDK 10 SP1 for X86-64
SLE SDK 10 SP1 for x86
  • graphviz >= 2.6-22.6
  • graphviz-devel >= 2.6-22.6
  • graphviz-tcl >= 2.6-22.6
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sle10-sp2-sdk.ppc
sle10-sp2-sdk.s390x
sle10-sp1-sdk.ia64
sle10-sp1-sdk.x86
sle10-sp1-sdk.ppc
sled10.x86
sle10-sp2-sdk.x86
sled10-sp2.x86
sle10-sp2-sdk.ia64
sled10-sp2.x86-64
sled10.x86-64
sle10-sp2-sdk.x86-64
ZYPP Patch Nr: 5688

© 2012 Novell