NULL pointer dereference in graphviz - CVE-2018-10196
Published: May 12, 2023
Vulnerability identifier: #VU76078
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10196
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the rebuild_vlists() function in lib/dotgen/conc.c within the dotgen library. A remote attacker can trick the victim to open a specially crafted file and crash the application.
Affected software
graphviz
Ubuntu
Fedora
graphviz (Ubuntu package)
libcdt5 (Ubuntu package)
libxdot4 (Ubuntu package)
libpathplan4 (Ubuntu package)
libgvpr2 (Ubuntu package)
libgvc6-plugins-gtk (Ubuntu package)
libgvc6 (Ubuntu package)
libcgraph6 (Ubuntu package)
graphviz
Isolation Segment
VMware Tanzu Application Service for VMs
Ubuntu
Fedora
graphviz (Ubuntu package)
libcdt5 (Ubuntu package)
libxdot4 (Ubuntu package)
libpathplan4 (Ubuntu package)
libgvpr2 (Ubuntu package)
libgvc6-plugins-gtk (Ubuntu package)
libgvc6 (Ubuntu package)
libcgraph6 (Ubuntu package)
graphviz
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2018-10196
Install update from vendor's website.
graphviz (Ubuntu package) - addressed in versions Ubuntu Pro, 2.38.012ubuntu2.1+esm1
Isolation Segment - addressed in versions 2.11.36, 2.13.21, 3.0.14, 4.0.5
VMware Tanzu Application Service for VMs - addressed in versions 2.11.42, 2.13.24, 3.0.14, 4.0.5
libcdt5 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libxdot4 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libpathplan4 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libgvpr2 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libgvc6-plugins-gtk (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libgvc6 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libcgraph6 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
graphviz - addressed in versions 2.40.1-11.fc27, 2.40.1-21.fc28, 2.40.1-22.fc28
Isolation Segment - addressed in versions 2.11.36, 2.13.21, 3.0.14, 4.0.5
VMware Tanzu Application Service for VMs - addressed in versions 2.11.42, 2.13.24, 3.0.14, 4.0.5
libcdt5 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libxdot4 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libpathplan4 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libgvpr2 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libgvc6-plugins-gtk (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libgvc6 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
libcgraph6 (Ubuntu package) - update to 2.38.012ubuntu2.1+esm1
graphviz - addressed in versions 2.40.1-11.fc27, 2.40.1-21.fc28, 2.40.1-22.fc28
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TWUEEJPMS5LAROYJYY6FREOTI6VPN3M4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N6VR2CT3LD52GWAQUZAOSEXSYE3O7HGN/
- https://gitlab.com/graphviz/graphviz/issues/1367
- https://bugzilla.redhat.com/show_bug.cgi?id=1579254
- https://usn.ubuntu.com/3731-1/
- https://lists.debian.org/debian-lts-announce/2021/05/msg00014.html