HTSlib through 1.10.2 allows out-of-bounds write access in vcfparseformat (called from vcfparse and vcfread).
[
{
"id": "CVE-2020-36403-7bd20209",
"target": {
"file": "vcf.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"89613930718482095295418375781556079303",
"106279598185036672352027483694167295946",
"41838877792325018614210971028286161697",
"141306006364824499810694766221609533097",
"138844591352443951934757920943778960221",
"52376274540466161438581399453999350696",
"38957599573841087259468579906854528539",
"30121372643580052949326471120180987497",
"17814336031281581577065574325381868517"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/samtools/htslib/commit/dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c",
"signature_version": "v1"
},
{
"id": "CVE-2020-36403-a2cb930f",
"target": {
"file": "vcf.c",
"function": "vcf_parse_format"
},
"digest": {
"length": 11588.0,
"function_hash": "196953719063338283441172377442625567381"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/samtools/htslib/commit/dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c",
"signature_version": "v1"
}
]