There is a heap-based buffer overflow in bmpcompress1row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-12578.json"