The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted vcf file.
https://usn.ubuntu.com/3974-1/
https://lists.debian.org/debian-lts-announce/2019/05/msg00039.html