PublicDateAtUSN: 2018-12-22 00:29:00 UTC Candidate: CVE-2018-20349 PublicDate: 2018-12-22 00:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20349 https://github.com/igraph/igraph/issues/1141 https://ubuntu.com/security/notices/USN-4644-1 Description: The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of service (application crash) via a crafted object. Ubuntu-Description: It was discovered that igraph mishandled certain malformed XML. An attacker could use this vulnerability to cause a denial of service (crash). Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_igraph: upstream_igraph: needs-triage precise/esm_igraph: DNE trusty_igraph: ignored (reached end-of-life) trusty/esm_igraph: DNE (trusty was needs-triage) xenial_igraph: released (0.7.1-2.1+deb9u1build0.16.04.1) bionic_igraph: released (0.7.1-2.1+deb9u1build0.18.04.1) cosmic_igraph: ignored (reached end-of-life) disco_igraph: not-affected (0.7.1-4) eoan_igraph: not-affected (0.7.1-4) focal_igraph: not-affected (0.7.1-4) groovy_igraph: not-affected (0.7.1-4) devel_igraph: not-affected (0.7.1-4)