Lucene search

K
osvGoogleOSV:USN-4835-1
HistoryMar 16, 2021 - 7:51 p.m.

vcftools vulnerabilities

2021-03-1619:51:26
Google
osv.dev
6
vcftools
vulnerabilities
input handling
memory allocation
use-after-free
crashes
leaks
code execution

AI Score

7

Confidence

High

EPSS

0.01

Percentile

83.5%

It was discovered that VCFtools improperly handled certain input. If a user
were tricked into opening a crafted input file, VCFtools could be made to
crash or possibly cause other unspecified impact.
(CVE-2018-11099, CVE-2018-11129, CVE-2018-11130)

It was discovered that VCFtools improperly handled memory
allocation/deallocation, resulting in a use-after-free vulnerability.
If a victim were tricked into opening a specially crafted VCF File, an
attacker could cause VCFtools to leak sensitive information or possibly
execute arbitrary code. (CVE-2019-1010127)

AI Score

7

Confidence

High

EPSS

0.01

Percentile

83.5%