Search CVE reports
1 – 6 of 6 results
CVE-2020-36403
Medium priorityHTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).
1 affected package
htslib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
htslib | Not affected | Not affected | Vulnerable | Needs evaluation | Needs evaluation |
CVE-2018-14329
Negligible priorityIn HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.
1 affected package
htslib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
htslib | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
CVE-2018-13845
Medium prioritySome fixes available 3 of 5
An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.
1 affected package
htslib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
htslib | — | Not affected | Not affected | Fixed | Fixed |
CVE-2018-13844
Low priority** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users would be aware...
1 affected package
htslib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
htslib | — | — | — | Not affected | Not affected |
CVE-2018-13843
Negligible priority** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's position is that the "failure to free memory" can be fixed in applications that use the HTSlib...
1 affected package
htslib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
htslib | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2017-1000206
Medium prioritySome fixes available 1 of 2
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution
1 affected package
htslib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
htslib | — | Not affected | Not affected | Not affected | Fixed |