Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2020-36403

Medium priority
Vulnerable

HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).

1 affected package

htslib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
htslib Not affected Not affected Vulnerable Needs evaluation Needs evaluation
Show less packages

CVE-2018-14329

Negligible priority
Vulnerable

In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.

1 affected package

htslib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
htslib Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-13845

Medium priority

Some fixes available 3 of 5

An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.

1 affected package

htslib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
htslib Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-13844

Low priority
Ignored

** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users would be aware...

1 affected package

htslib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
htslib Not affected Not affected
Show less packages

CVE-2018-13843

Negligible priority
Ignored

** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's position is that the "failure to free memory" can be fixed in applications that use the HTSlib...

1 affected package

htslib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
htslib Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-1000206

Medium priority

Some fixes available 1 of 2

samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution

1 affected package

htslib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
htslib Not affected Not affected Not affected Fixed
Show less packages