An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wavpack | Jun 13, 2018 | Apr 29, 2018 |
| Debian | — | Upgrade wavpack | May 11, 2018 | Apr 29, 2018 |
| Freebsd | — | Upgrade wavpack | May 14, 2018 | May 11, 2018 |
| Suse | — | Upgrade wavpackUpgrade libwavpack1Upgrade libwavpack1-32bitUpgrade wavpack-devel | Jan 22, 2021 | Apr 29, 2018 |
| Ubuntu | — | Upgrade wavpack | May 12, 2018 | Apr 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub