First published: Fri Mar 29 2019(Updated: )
BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/bwa | 0.7.17-6 0.7.17-7 0.7.18-1 | |
Burrow-Wheeler Aligner | <2019-01-23 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10269 is classified as a critical vulnerability due to the potential for exploitation via stack-based buffer overflow.
To fix CVE-2019-10269, update to a version of BWA later than 2019-01-23.
CVE-2019-10269 affects versions of BWA prior to 2019-01-23.
CVE-2019-10269 impacts BWA on Debian and Ubuntu environments.
CVE-2019-10269 involves a stack-based buffer overflow in the bns_restore function due to long sequence names in .alt files.