There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12601.json"