PT-2018-12217 · Htslib · Htslib

Fcorleone

·

Published

2018-07-10

·

Updated

2024-08-05

·

CVE-2018-13844

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HTSlib version 1.8
Description An issue has been found in HTSlib, which is a memory leak in fai read in faidx.c. It has been disputed that this issue exists in the test harness and that HTSlib users would be aware of the need to destruct the object returned by fai load() in their own code.
Recommendations For HTSlib version 1.8, users should ensure to properly destruct the object returned by fai load() in their own code to mitigate the memory leak issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2018-13844

Affected Products

Htslib