graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files. NOTE: this issue was originally associated with a different CVE identifier, CVE-2005-2965, which had been used for multiple different issues. This is the correct identifier.
2005-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 3.6 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | graphviz | graphviz | ≤ 2.2 | Yes |
Application | graphviz | graphviz | 1.5.1 | Yes |
Application | graphviz | graphviz | 1.5.2 | Yes |
Application | graphviz | graphviz | 1.5.3 | Yes |
Application | graphviz | graphviz | 1.7.5.1 | Yes |
Application | graphviz | graphviz | 1.7.5.2 | Yes |
Application | graphviz | graphviz | 1.7.5.3 | Yes |
Application | graphviz | graphviz | 1.7.5.4 | Yes |
Application | graphviz | graphviz | 1.7.5.5 | Yes |
Application | graphviz | graphviz | 1.7.5.6 | Yes |
Application | graphviz | graphviz | 1.7.5.7 | Yes |
Application | graphviz | graphviz | 1.7.5_0.1 | Yes |
Application | graphviz | graphviz | 1.7.5_0.2 | Yes |
Application | graphviz | graphviz | 1.7.5_0.3 | Yes |
Application | graphviz | graphviz | 1.7.16.1 | Yes |
Application | graphviz | graphviz | 1.7.16.2 | Yes |
Application | graphviz | graphviz | 1.8.5.1 | Yes |
Application | graphviz | graphviz | 1.8.5.2 | Yes |
Application | graphviz | graphviz | 1.8.9.1 | Yes |
Application | graphviz | graphviz | 1.10_2003-09-15_0415_1 | Yes |
Application | graphviz | graphviz | 1.10_2003-09-15_0415_2 | Yes |
Application | graphviz | graphviz | 1.12.1 | Yes |
Application | graphviz | graphviz | 1.12.2 | Yes |
Application | graphviz | graphviz | 1.12.3 | Yes |
Application | graphviz | graphviz | 1.14.1 | Yes |
Application | graphviz | graphviz | 1.16.1 | Yes |