Stack-based buffer overflow in Burrow-Wheeler Aligner - CVE-2019-10269
Published: August 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the bns_restore function in bntseq.c via a long sequence name in a .alt file. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
bwa (Ubuntu package)
bwa
bwa-debuginfo
bwa-debugsource
Opensuse
openEuler
How to mitigate CVE-2019-10269
bwa - update to 0.7.17-2
bwa-debuginfo - update to 0.7.17-2
bwa-debugsource - update to 0.7.17-2