WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/f68a9555b548306c5b1ee45199ccdc4a16a6101b.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade wavpackUpgrade wavpack-devel | May 4, 2022 | Jul 11, 2019 |
| Alpine Linux | — | Upgrade wavpack | Nov 8, 2019 | Jul 11, 2019 |
| Centos_linux | — | Upgrade wavpack-debuginfoUpgrade wavpackUpgrade wavpack-debugsource | Apr 29, 2020 | Jul 11, 2019 |
| Debian | — | Upgrade wavpack | Jan 18, 2021 | Jul 11, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade wavpack | Sep 30, 2019 | Jul 11, 2019 |
| Oracle_linux | — | Upgrade wavpackUpgrade wavpack-devel | Oct 5, 2022 | Aug 6, 2019 |
| Redhat_linux | — | Upgrade wavpack-develUpgrade wavpack-debuginfoUpgrade wavpack-debugsourceUpgrade wavpack | Apr 29, 2020 | Jul 11, 2019 |
| Rocky_linux | — | Upgrade wavpack-debugsourceUpgrade wavpackUpgrade wavpack-develUpgrade wavpack-debuginfo | Mar 12, 2024 | Jul 11, 2019 |
| Ubuntu | — | Upgrade libwavpack1Upgrade wavpack | Jul 17, 2019 | Jul 11, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub