PT-2018-3621 · At&T+4 · Graphviz+4

Andrej Nemec

·

Published

2018-01-09

·

Updated

2025-01-17

·

CVE-2018-10196

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Graphviz version 2.40.1
Description The issue is related to a NULL pointer dereference vulnerability in the rebuild vlists function in lib/dotgen/conc.c in the dotgen library. This vulnerability allows remote attackers to cause a denial of service, resulting in an application crash, via a crafted file.
Recommendations For Graphviz version 2.40.1, consider disabling the rebuild vlists function in lib/dotgen/conc.c as a temporary workaround until a patch is available. Restrict access to crafted files that could exploit this vulnerability to minimize the risk of denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1699
ALT-PU-2020-1430
ALT-PU-2020-3007
ALT-PU-2025-1286
BDU:2021-01391
CVE-2018-10196
DLA-2659-1
MGASA-2018-0307
OPENSUSE-SU-2020:1294-1
OPENSUSE-SU-2020:1303-1
OPENSUSE-SU-2020_1294-1
OPENSUSE-SU-2020_1303-1
OPENSUSE-SU-2024:10821-1
SUSE-SU-2020:14524-1
SUSE-SU-2020:2346-1
SUSE-SU-2020:3090-1
SUSE-SU-2020_14524-1
SUSE-SU-2020_2346-1
SUSE-SU-2020_3090-1
USN-5264-1
USN-5971-1

Affected Products

Alt Linux
Graphviz
Linuxmint
Suse
Ubuntu