OSV-2023-1370

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/htslib/OSV-2023-1370.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-1370
Published
2023-12-29T00:14:11.001809Z
Modified
2024-04-29T11:26:13.704078Z
Summary
Heap-buffer-overflow in process_one_read
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=65383

Crash type: Heap-buffer-overflow READ 1
Crash state:
process_one_read
cram_encode_container
cram_flush_container_mt
References

Affected packages

OSS-Fuzz / htslib

Package

Name
htslib
Purl
pkg:generic/htslib

Affected ranges

Type
GIT
Repo
https://github.com/samtools/htslib.git
Events

Affected versions

1.*

1.19

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "fixed_range": "61b037bb881e85259f8df30c78d99ad3a357ed52:67f3ab0f3707f8cacb0ad3571fd04eb7a14d5d58"
}