CVE-2018-10196
Summary
| CVE | CVE-2018-10196 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-30 21:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1579254 – (CVE-2018-10196) CVE-2018-10196 graphviz: NULL pointer dereference in rebuild_vlis |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| null derefence in rebuild_vlist (#1367) · Issues · graphviz / graphviz · GitLab |
MISC |
gitlab.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 27 Update: graphviz-2.40.1-11.fc27 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-3731-1: LFTP vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 27 Update: graphviz-2.40.1-11.fc27 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 28 Update: graphviz-2.40.1-22.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2659-1] graphviz security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 28 Update: graphviz-2.40.1-22.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178596 Debian Security Update for graphviz (DLA 2659-1)
- 199473 Ubuntu Security Notification for Graphviz Vulnerabilities (USN-5971-1)
- 670283 EulerOS Security Update for graphviz (EulerOS-SA-2021-1793)
- 670914 EulerOS Security Update for graphviz (EulerOS-SA-2021-1303)