PT-2019-11474 · Atgc+1 · Vcftools+1

Mssalvatore

·

Published

2019-07-25

·

Updated

2021-03-16

·

CVE-2019-1010127

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: VCFTools versions prior to 0.1.15
Description: The issue is related to a use-after-free problem, which can lead to a Denial of Service or possibly other impacts such as code execution or information disclosure. The component affected is the header::add FILTER descriptor method in header.cpp. The attack vector involves the victim opening a specially crafted VCF file.
Recommendations: For versions prior to 0.1.15, update to version 0.1.15 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the header::add FILTER descriptor method in header.cpp until a patch is available. Restrict access to specially crafted VCF files to minimize the risk of exploitation.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1010127
USN-4835-1

Affected Products

Ubuntu
Vcftools