An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wavpack | Jun 13, 2018 | Apr 29, 2018 |
| Debian | — | Upgrade wavpack | May 11, 2018 | Apr 29, 2018 |
| Freebsd | — | Upgrade wavpack | May 14, 2018 | May 11, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 29, 2018 |
| Suse | — | Upgrade wavpackUpgrade wavpack-develUpgrade libwavpack1-32bitUpgrade libwavpack1 | Jan 22, 2021 | Apr 29, 2018 |
| Ubuntu | — | Upgrade wavpack | May 12, 2018 | Apr 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub