{"id":"CVE-2020-36403","details":"HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).","modified":"2026-04-11T09:46:25.435206Z","published":"2021-07-01T03:15:07.893Z","related":["openSUSE-SU-2021:1177-1"],"references":[{"type":"ADVISORY","url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/htslib/OSV-2020-955.yaml"},{"type":"FIX","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24097"},{"type":"FIX","url":"https://github.com/samtools/htslib/commit/dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c"},{"type":"EVIDENCE","url":"https://github.com/samtools/htslib/pull/1447"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/samtools/htslib","events":[{"introduced":"0"},{"last_affected":"fd0f89554459b78c07303e2c8a42acacd6851b46"},{"fixed":"dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.10.2"}]}}],"versions":["0.2.0-rc10","0.2.0-rc11","0.2.0-rc12","0.2.0-rc2","0.2.0-rc3","0.2.0-rc4","0.2.0-rc5","0.2.0-rc6","0.2.0-rc7","0.2.0-rc8","0.2.0-rc9","1.0","1.1","1.10","1.10.1","1.10.2","1.2","1.2.1","1.3","1.3.1","1.3.2","1.4","1.4.1","1.5","1.6","1.7","1.8","1.9","stable1","stable2","vcf-direct-final"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36403.json","vanir_signatures_modified":"2026-04-11T09:46:25Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["89613930718482095295418375781556079303","106279598185036672352027483694167295946","41838877792325018614210971028286161697","141306006364824499810694766221609533097","138844591352443951934757920943778960221","52376274540466161438581399453999350696","38957599573841087259468579906854528539","30121372643580052949326471120180987497","17814336031281581577065574325381868517"],"threshold":0.9},"id":"CVE-2020-36403-7bd20209","signature_type":"Line","signature_version":"v1","source":"https://github.com/samtools/htslib/commit/dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c","target":{"file":"vcf.c"}},{"target":{"function":"vcf_parse_format","file":"vcf.c"},"deprecated":false,"digest":{"function_hash":"196953719063338283441172377442625567381","length":11588},"id":"CVE-2020-36403-a2cb930f","signature_type":"Function","signature_version":"v1","source":"https://github.com/samtools/htslib/commit/dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}