Bug 1093447 (CVE-2018-10196) - VUL-1: CVE-2018-10196: graphviz: NULL derefence in rebuild_vlis
Summary: VUL-1: CVE-2018-10196: graphviz: NULL derefence in rebuild_vlis
Status: RESOLVED FIXED
Alias: CVE-2018-10196
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/205847/
Whiteboard: CVSSv3:SUSE:CVE-2018-10196:3.3:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-05-16 06:28 UTC by Johannes Segitz
Modified: 2024-05-08 13:19 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
Proposed pach (38.63 KB, patch)
2018-05-16 06:28 UTC, Johannes Segitz
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-05-16 06:28:29 UTC
Created attachment 770377 [details]
Proposed pach

CVE-2018-10196

Details in https://issuetracker.google.com/issues/77810342

We also still have the aborts() in our code, we should remove them too.

SLE 11/12 affected.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10196
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-10196.html
Comment 1 Thomas Renninger 2019-02-19 15:09:53 UTC
Fix is approved, but it is not yet pushed mainline.
I'll wait until it shows up in the git repository.
Comment 2 Alexander Bergmann 2019-04-23 15:18:08 UTC
There is still ongoing upstream discussion about a possible fix.

https://gitlab.com/graphviz/graphviz/merge_requests/1303

Waiting for upstream confirmation about the situation.
Comment 4 OBSbugzilla Bot 2020-06-25 12:10:07 UTC
This is an autogenerated message for OBS integration:
This bug (1093447) was mentioned in
https://build.opensuse.org/request/show/817045 15.1 / graphviz
Comment 5 Christian Vögl 2020-06-25 12:52:04 UTC
Upstream did a manual merge of the fix quite some time ago, which is now back-ported to SLE-11 and later.
Comment 6 Swamp Workflow Management 2020-08-26 19:14:30 UTC
SUSE-SU-2020:2346-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1093447
CVE References: CVE-2018-10196
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP1 (src):    graphviz-addons-2.40.1-6.6.8
SUSE Linux Enterprise Module for Development Tools 15-SP1 (src):    graphviz-addons-2.40.1-6.6.8
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    graphviz-2.40.1-6.6.4
SUSE Linux Enterprise High Availability 15-SP1 (src):    graphviz-addons-2.40.1-6.6.8
SUSE Linux Enterprise High Availability 15 (src):    graphviz-addons-2.40.1-6.6.8

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2020-08-30 10:14:50 UTC
openSUSE-SU-2020:1294-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1093447
CVE References: CVE-2018-10196
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    graphviz-2.40.1-lp151.6.6.1, graphviz-addons-2.40.1-lp151.6.6.1
Comment 8 Swamp Workflow Management 2020-08-31 04:13:38 UTC
openSUSE-SU-2020:1303-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1093447
CVE References: CVE-2018-10196
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    graphviz-2.40.1-lp152.7.7.1, graphviz-addons-2.40.1-lp152.7.7.1
Comment 9 Swamp Workflow Management 2020-10-29 17:20:01 UTC
SUSE-SU-2020:3090-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1093447
CVE References: CVE-2018-10196
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    graphviz-2.28.0-29.3.8
SUSE Linux Enterprise Server 12-SP5 (src):    graphviz-2.28.0-29.3.8, graphviz-plugins-2.28.0-29.3.17
SUSE Linux Enterprise High Availability 12-SP5 (src):    graphviz-plugins-2.28.0-29.3.17
SUSE Linux Enterprise High Availability 12-SP4 (src):    graphviz-plugins-2.28.0-29.3.17
SUSE Linux Enterprise High Availability 12-SP3 (src):    graphviz-plugins-2.28.0-29.3.17

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2020-10-30 14:16:36 UTC
SUSE-SU-2020:14524-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1093447
CVE References: CVE-2018-10196
JIRA References: 
Sources used:
SUSE Linux Enterprise High Availability Extension 11-SP4 (src):    graphviz-plugins-2.20.2-8.3.6

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.