{"id":"UBUNTU-CVE-2020-36403","details":"HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).","modified":"2026-04-22T12:41:27.923931Z","published":"2021-07-01T03:15:00Z","upstream":["CVE-2020-36403"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-36403"},{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24097"},{"type":"REPORT","url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/htslib/OSV-2020-955.yaml"},{"type":"REPORT","url":"https://github.com/samtools/htslib/commit/dcd4b7304941a8832fba2d0fc4c1e716e7a4e72c"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-36403"}],"affected":[{"package":{"name":"htslib","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/htslib@0.2.0~rc3-1ubuntu0.1~esm1?arch=source&distro=esm-infra-legacy/trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.0~rc3-1","0.2.0~rc3-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.2.0~rc3-1ubuntu0.1~esm1","binary_name":"htslib-test"},{"binary_name":"libhts0","binary_version":"0.2.0~rc3-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36403.json"}},{"package":{"name":"htslib","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/htslib@1.2.1-2ubuntu1+esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.1-1","1.2.1-2","1.2.1-2ubuntu1","1.2.1-2ubuntu1+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"htslib-test","binary_version":"1.2.1-2ubuntu1+esm1"},{"binary_name":"libhts1","binary_version":"1.2.1-2ubuntu1+esm1"},{"binary_name":"tabix","binary_version":"1.2.1-2ubuntu1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36403.json"}},{"package":{"name":"htslib","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/htslib@1.7-2ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5-1","1.5-4ubuntu1","1.6-3ubuntu1","1.6-4","1.6-4build1","1.7-2","1.7-2ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.7-2ubuntu0.1~esm1","binary_name":"htslib-test"},{"binary_name":"libhts2","binary_version":"1.7-2ubuntu0.1~esm1"},{"binary_name":"tabix","binary_version":"1.7-2ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36403.json"}},{"package":{"name":"htslib","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/htslib@1.10.2-3ubuntu0.1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9-10","1.9-11","1.9-12","1.10.2-2ubuntu1","1.10.2-2ubuntu2","1.10.2-3","1.10.2-3ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"htslib-test","binary_version":"1.10.2-3ubuntu0.1"},{"binary_name":"libhts3","binary_version":"1.10.2-3ubuntu0.1"},{"binary_name":"tabix","binary_version":"1.10.2-3ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36403.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}