First published: Tue Aug 06 2019(Updated: )
It was discovered that Burrows-Wheeler Aligner (BWA) mishandled certain crafted .alt files. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/bwa | <0.7.17-3~ubuntu0.19.04.1 | 0.7.17-3~ubuntu0.19.04.1 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/bwa | <0.7.17-1ubuntu0.1 | 0.7.17-1ubuntu0.1 |
Ubuntu OpenSSH Client | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4087-1 has a high severity rating due to the potential for denial of service or arbitrary code execution.
USN-4087-1 affects BWA by mishandling crafted .alt files, which can lead to a crash or compromise.
To fix USN-4087-1, upgrade BWA to version 0.7.17-3~ubuntu0.19.04.1 on Ubuntu 19.04 or 0.7.17-1ubuntu0.1 on Ubuntu 18.04.
Yes, USN-4087-1 can potentially be exploited remotely by an attacker using specially crafted .alt files.
The affected versions in USN-4087-1 include BWA versions prior to 0.7.17-3~ubuntu0.19.04.1 and 0.7.17-1ubuntu0.1.