The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wavpack | Aug 30, 2017 | Mar 14, 2017 |
| Debian | — | Upgrade wavpack | Jul 30, 2024 | Mar 14, 2017 |
| Freebsd | — | Upgrade wavpack | Feb 19, 2017 | Feb 18, 2017 |
| Suse | — | Upgrade wavpackUpgrade wavpack-develUpgrade libwavpack1 | Mar 10, 2018 | Jan 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub