Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2020-0013 Moderate: Addressing igraph Denial Of Service Risk

mageia
Calendar Grey January 5, 2020
Dist Mageia Esm H88
On 05 Jan 2020, Mageia released enhanced igraph packages that effectively address significant security vulnerabilities, thwarting potential application failures.
Updated igraph packages fix security vulnerability: The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to...

Summary

Updated igraph packages fix security vulnerability:
The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of service (application crash) via a crafted object (CVE-2018-20349).

References

- https://bugs.mageia.org/show_bug.cgi?id=25937

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NCGDUNQYLSZLSGN6JJBORVFW46U3A75Y/

- https://www.cve.org/CVERecord?id=CVE-2018-20349

Resolution

SRPMS

- 7/core/igraph-0.7.1-2.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 05 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0013.html
Type: security
CVE: CVE-2018-20349

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here