{"id":"CVE-2018-10196","details":"NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.","modified":"2026-04-09T06:03:17.959503Z","published":"2018-05-30T21:29:00.283Z","related":["MGASA-2018-0307","SUSE-SU-2020:14524-1","SUSE-SU-2020:2346-1","SUSE-SU-2020:3090-1","openSUSE-SU-2020:1294-1","openSUSE-SU-2020:1303-1","openSUSE-SU-2024:10821-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2021/05/msg00014.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6VR2CT3LD52GWAQUZAOSEXSYE3O7HGN/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TWUEEJPMS5LAROYJYY6FREOTI6VPN3M4/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3731-1/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1579254"},{"type":"FIX","url":"https://gitlab.com/graphviz/graphviz/issues/1367"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/graphviz/graphviz","events":[{"introduced":"0"},{"last_affected":"67cd2e5121379a38e0801cc05cce5033f8a2a609"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.40.1"}]}}],"versions":["2.38.0","2.40.0","2.40.1","TRAVIS_CI_BUILD_EXPERIMENTAL"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10196.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"27"}]},{"events":[{"introduced":"0"},{"last_affected":"28"}]},{"events":[{"introduced":"0"},{"last_affected":"14.04"}]},{"events":[{"introduced":"0"},{"last_affected":"16.04"}]},{"events":[{"introduced":"0"},{"last_affected":"18.04"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}