跳转到帖子

Amazon Linux 2023: CVE-2023-46045: Medium priority package update for graphviz

recommended_posts

发布于
  • 超级管理员

Amazon Linux 2023: CVE-2023-46045: Medium priority package update for graphviz

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
02/02/2024
Created
02/14/2025
Added
02/14/2025
Modified
02/14/2025

Description

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

Solution(s)

  • amazon-linux-2023-upgrade-graphviz
  • amazon-linux-2023-upgrade-graphviz-debuginfo
  • amazon-linux-2023-upgrade-graphviz-debugsource
  • amazon-linux-2023-upgrade-graphviz-devel
  • amazon-linux-2023-upgrade-graphviz-doc
  • amazon-linux-2023-upgrade-graphviz-gd
  • amazon-linux-2023-upgrade-graphviz-gd-debuginfo
  • amazon-linux-2023-upgrade-graphviz-graphs
  • amazon-linux-2023-upgrade-graphviz-java
  • amazon-linux-2023-upgrade-graphviz-java-debuginfo
  • amazon-linux-2023-upgrade-graphviz-lua
  • amazon-linux-2023-upgrade-graphviz-lua-debuginfo
  • amazon-linux-2023-upgrade-graphviz-ocaml
  • amazon-linux-2023-upgrade-graphviz-ocaml-debuginfo
  • amazon-linux-2023-upgrade-graphviz-perl
  • amazon-linux-2023-upgrade-graphviz-perl-debuginfo
  • amazon-linux-2023-upgrade-graphviz-tcl
  • amazon-linux-2023-upgrade-graphviz-tcl-debuginfo

References

  • https://attackerkb.com/topics/cve-2023-46045
  • CVE - 2023-46045
  • https://alas.aws.amazon.com/AL2023/ALAS-2024-527.html
  • 查看数 715
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…