USN-4835-1: VCFtools vulnerabilities
16 March 2021
VCFtools could be made to crash if it opened a specially crafted file.
Releases
Packages
- vcftools - Collection of tools to work with VCF files
Details
It was discovered that VCFtools improperly handled certain input. If a user
were tricked into opening a crafted input file, VCFtools could be made to
crash or possibly cause other unspecified impact.
(CVE-2018-11099, CVE-2018-11129, CVE-2018-11130)
It was discovered that VCFtools improperly handled memory
allocation/deallocation, resulting in a use-after-free vulnerability.
If a victim were tricked into opening a specially crafted VCF File, an
attacker could cause VCFtools to leak sensitive information or possibly
execute arbitrary code. (CVE-2019-1010127)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
vcftools
-
0.1.15-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
vcftools
-
0.1.11+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
Related notices
- USN-3974-1: vcftools