igraph could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4644-1 November 24, 2020 igraph vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: igraph could be made to crash if it opened a specially crafted file. Software Description: - igraph: None Details: It was discovered that igraph mishandled certain malformed XML. An attacker could use this vulnerability to cause a denial of service (crash). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libigraph0v5 0.7.1-2.1+deb9u1build0.18.04.1 Ubuntu 16.04 LTS: libigraph0v5 0.7.1-2.1+deb9u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4644-1 CVE-2018-20349 Package Information: https://launchpad.net/ubuntu/+source/igraph/0.7.1-2.1+deb9u1build0.18.04.1 https://launchpad.net/ubuntu/+source/igraph/0.7.1-2.1+deb9u1build0.16.04.1 . Ubuntu Security Notice USN-4644-1 highlights a critical flaw in the igraph library affecting graph analysis, enabling denial of service via malformed XML input. igraph Vulnerability, Ubuntu Update, Denial of Service. . LinuxSecurity.com Team
An issue has been found in igraph, a library for creating and manipulating graphs. A NULL pointer dereference vulneribility was detected in . Package : igraph Version : 0.7.1-2+deb8u1 CVE ID : CVE-2018-20349 An issue has been found in igraph, a library for creating and manipulating graphs. A NULL pointer dereference vulneribility was detected in igraph_i_strdiff(). For Debian 8 "Jessie", this problem has been fixed in version 0.7.1-2+deb8u1. We recommend that you upgrade your igraph packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade igraph package to version 0.7.1-3+deb8u1 to address critical vulnerabilities in Debian LTS.. igraph Security Update, Debian LTS, NULL Pointer Compliance. . Severity: Critical. LinuxSecurity.com Team
Patch for CVE-2018-20349. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-060e7b383c 2019-08-14 01:04:58.755409 --------------------------------------------------------------------------------Name : igraph Product : Fedora 30 Version : 0.7.1 Release : 12.fc30 URL : Summary : Library for creating and manipulating graphs Description : igraph wants to be an efficient platform for 1) complex network analysis and 2) developing and implementing graph algorithms. It provides flexible and efficient data structures for graphs and related tasks. It also provides implementation to many classic and new graph algorithms like: maximum flows, graph isomorphism, scale-free networks, community structure finding, etc. --------------------------------------------------------------------------------Update Information: Patch for CVE-2018-20349 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 5 2019 Gwyn Ciesla - 0.7.1-12 - Patch for CVE-2018-20349 * Thu Jul 25 2019 Fedora Release Engineering - 0.7.1-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1664022 - CVE-2018-20349 igraph: NULL pointer dereference in igraph_i_strdiff function resulting in a denial of service [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1664022 [ 2 ] Bug #1664021 - CVE-2018-20349 igraph: NULL pointer dereference in igraph_i_strdiff function resulting in a denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1664021 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-060e7b383c' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.