CVE-2018-11129: Vcftools Project Vcftools
High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.
The header::add_INFO_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted vcf file.
Affected products
- Vcftools Project Vcftools: version 0.1.15 only
Published 2018-05-17. Last modified 2026-06-17.