CVE-2018-10196: Null Pointer Dereference
A NULL pointer dereference vulnerability was found in graphviz in the rebuildvlists function. A maliciously crafted file could cause the application to crash.
References:
https://issuetracker.google.com/issues/77810342
Upstream issue:
https://gitlab.com/graphviz/graphviz/issues/1367
Other sources
NULL pointer dereference vulnerability in the rebuildvlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10196?
CVE-2018-10196 is classified as a low severity vulnerability due to its potential to cause application crashes.
How do I fix CVE-2018-10196?
To fix CVE-2018-10196, upgrade to a patched version of Graphviz after verifying the application's compatibility.
Which versions of Graphviz are affected by CVE-2018-10196?
CVE-2018-10196 affects Graphviz version 2.40.1 specifically.
What could happen if CVE-2018-10196 is exploited?
If exploited, CVE-2018-10196 may lead to the application crashing when processing a maliciously crafted file.
Is CVE-2018-10196 related to any specific operating systems?
CVE-2018-10196 affects Graphviz installations on Fedora and Ubuntu operating systems.