CVE-2019-9904 PUBLISHED

An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.

EPSS 0.08% · 23.4th percentile

Risk Scores

EPSS Score
0.08%
23.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSgraphviz2.38.0-16ubuntu2, 2.40.1-0ubuntu6, 2.40.1-0ubuntu5
Ubuntu:25.10graphviz2.42.4-3build2, 2.42.4-3build1, 2.42.4-3
Ubuntu:Pro:22.04:LTSgraphviz2.42.2-6ubuntu0.1, 0, 2.42.2-5
Ubuntu:Pro:20.04:LTSgraphviz2.40.1-7build1, 2.40.1-7build2, 2.42.2-3
Ubuntu:Pro:14.04:LTSgraphviz2.36.0-0ubuntu3, 2.36.0-0ubuntu2, 0
Ubuntu:Pro:16.04:LTSgraphviz2.38.0-12ubuntu2.1+esm1, 2.38.0-12ubuntu2.1+esm2, 2.38.0-10build1
Ubuntu:24.04:LTSgraphviz2.42.2-9, 2.42.2-9ubuntu0.1, 2.42.2-9build1

Timeline

References

Open in Interactive Console →