CVE-2019-10269

NameCVE-2019-10269
DescriptionBWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs926014

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bwa (PTS)jessie0.7.10-1fixed
stretch0.7.15-2+deb9u1fixed
buster, sid0.7.17-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bwasource(unstable)0.7.17-3low926014
bwasourcejessie(not affected)
bwasourcestretch0.7.15-2+deb9u1high

Notes

[jessie] - bwa <not-affected> (vulnerable code is not present)
https://github.com/lh3/bwa/pull/232
https://github.com/lh3/bwa/commit/20d0a13092aa4cb73230492b05f9697d5ef0b88e

Search for package or bug name: Reporting problems