PT-2019-11474 · Atgc+1 · Vcftools+1
Mssalvatore
·
Published
2019-07-25
·
Updated
2021-03-16
·
CVE-2019-1010127
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
VCFTools versions prior to 0.1.15
Description:
The issue is related to a use-after-free problem, which can lead to a Denial of Service or possibly other impacts such as code execution or information disclosure. The component affected is the header::add FILTER descriptor method in header.cpp. The attack vector involves the victim opening a specially crafted VCF file.
Recommendations:
For versions prior to 0.1.15, update to version 0.1.15 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the header::add FILTER descriptor method in header.cpp until a patch is available. Restrict access to specially crafted VCF files to minimize the risk of exploitation.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu
Vcftools