CVE-2018-10196

Published

Severity

CVSS v3:
5.5 MEDIUM
CVSS v2:
4.3 MEDIUM

Description

NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:graphviz:graphviz:2.40.1:*:*:*:*:*:*:*n/an/a2.40.1
cpe:2.3:o:fedoraproject:fedora:27:*:*:*:*:*:*:*n/an/a27
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*n/an/a28
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*n/an/a16.04
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*n/an/a14.04
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*n/an/a18.04

External Links