5.5
CVSSv3

CVE-2018-10196

Published: 30/05/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote malicious users to cause a denial of service (application crash) via a crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

graphviz graphviz 2.40.1

fedoraproject fedora 27

fedoraproject fedora 28

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

Vendor Advisories

Debian Bug report logs - #898841 graphviz: CVE-2018-10196 Package: src:graphviz; Maintainer for src:graphviz is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 16 May 2018 13:00:02 UTC Severity: normal Tags: security, upstream Found in version graphviz/240 ...
Several security issues were fixed in graphviz ...