The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of service (application crash) via a crafted object.
https://lists.debian.org/debian-lts-announce/2019/12/msg00038.html