UBUNTU-CVE-2019-1010127
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-1010127
UBUNTU-CVE-2019-1010127
Summary:
Details: VCFTools vcftools prior to version 0.1.15 is affected by: Use-after-free. The impact is: Denial of Service or possibly other impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.
References: https://ubuntu.com/security/CVE-2019-1010127, https://docs.google.com/document/d/e/2PACX-1vQJveVcGMp_NMdBY5Je2K2k63RoCYznvKjJk5u1wJRmLotvwQkG5qiqZjpABcOkjzj49wkwGweiFwrc/pub, https://ubuntu.com/security/notices/USN-4835-1, https://www.cve.org/CVERecord?id=CVE-2019-1010127
Affected packages
Package
Name: vcftools
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu0.1~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
