DescriptionVCFTools vcftools prior to version 0.1.15 is affected by: Use-after-free. The impact is: Denial of Service or possibly other impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.
Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vcftools (PTS)buster0.1.16-1fixed
bookworm, sid0.1.16-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs

Notes (v0.1.16) (v0.1.16) (v0.1.16) (fix for typo in warning log message))
CVE-2019-1010127 is a different issue than CVE-2018-11099, CVE-2018-11129 and
CVE-2018-11130 but covered with same set of upstream commits.

