Logo
componentgraphviz
Name
graphviz
Version
2.50.0
Type
library
Description
Graph Visualization Tools
Licenses
EPL-1.0
PURL
-
CPE
cpe:2.3:*:*:graphviz:2.50.0:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
15.0.0
scarthgap
8.1.0

Patches#


#
Title
Author
Resolve
1
gvc gvconfig_plugin_install_from_config: more tightly scope
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2023-46045
2
gvc: detect plugin installation failure and display an error
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2023-46045
3
plugin/pango: Include freetype headers explicitly
Khem Raj <raj.khem@gmail.com>
4
Use native mkdefs
=?UTF-8?q?Andreas=20M=C3=BCller?= <schnitzeltony@gmail.com>
5
gvc gvconfig_plugin_install_from_config: more tightly scope
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2023-46045
6
Set use_tcl to be empty string if tcl is disabled
Khem Raj <raj.khem@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Patched
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.