oss-sec mailing list archives

Re: CVE Request: graphviz: stack-based buffer overflow in yyerror()


From: cve-assign () mitre org
Date: Tue, 7 Jan 2014 17:19:07 -0500 (EST)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

an error within the "yyerror()"
function (lib/cgraph/scan.l) and can be exploited to cause a stack-based
buffer overflow via a specially crafted file.

Use CVE-2014-0978.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJSzH0dAAoJEKllVAevmvmsdcAIALBfNun5cNjVGVEVmWYQIncL
cZIWWhasJDtZoSSP7sEqSWUnTvIft/9Ke6O6dCykngQo6kIEQYqUfxeKpB2c+Asi
b144u4i7nLyustXMCAHkJ58Z2sr5+IfvrjY8g7MzCQU3eRVw4O4NcNGK7qmU3nyv
D3YX3b4ON2a6FWmGNFYmo9aJ7x1suMIjXKPqM7m//+6qpEdSH7kETMvLR86lJZuj
L2FBvbPVvpN8VgAMrASONQBMsVAaqXDSuizQgfAxqktqBCO/8lSsJ+0kE4ybMHkr
gN1hL4z+mo7gkVqeaemtds41ZaM51pAQvp+vkUGx3y35SppqcxiSr55GqjZTBts=
=F0p9
-----END PGP SIGNATURE-----


Current thread: