{"id":"RSEC-2023-4","summary":"NULL pointer dereference vulnerability","details":"The igraph R package, through version 0.7.1, is susceptible to a vulnerability identified in the igraph_i_strdiff function within igraph_trie.c. This vulnerability can lead to a NULL pointer dereference, potentially exploited by attackers to cause a denial of service, resulting in an application crash. Users of the igraph package should take necessary precautions and consider updating to a patched version to mitigate this security risk.","modified":"2025-05-19T19:43:47.425900Z","published":"2023-10-04T03:23:51.600Z","upstream":["CVE-2018-20349"],"references":[{"type":"WEB","url":"https://github.com/igraph/igraph/issues/1141"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2018-20349"}],"affected":[{"package":{"name":"igraph","ecosystem":"CRAN","purl":"pkg:cran/igraph"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.7.1"},{"fixed":"1.2.2-2"}]}],"versions":["0.7.1","1.0.0","1.0.1","1.1.1","1.1.2","1.2.1","1.2.2"],"database_specific":{"source":"https://github.com/RConsortium/r-advisory-database/blob/main/vulns/igraph/RSEC-2023-4.yaml"}}],"schema_version":"1.7.3"}