WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/f68a9555b548306c5b1ee45199ccdc4a16a6101b.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade wavpackUpgrade wavpack-devel | May 4, 2022 | Jul 11, 2019 |
| Alpine Linux | — | Upgrade wavpack | Nov 8, 2019 | Jul 11, 2019 |
| Centos_linux | — | Upgrade wavpack-debuginfoUpgrade wavpackUpgrade wavpack-debugsource | Apr 29, 2020 | Jul 11, 2019 |
| Debian | — | Upgrade wavpack | Jan 18, 2021 | Jul 11, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade wavpack | Sep 30, 2019 | Jul 11, 2019 |
| Oracle_linux | — | Upgrade wavpackUpgrade wavpack-devel | Oct 5, 2022 | Aug 6, 2019 |
| Redhat_linux | — | Upgrade wavpack-develUpgrade wavpack-debugsourceUpgrade wavpack-debuginfoUpgrade wavpack | Apr 29, 2020 | Jul 11, 2019 |
| Rocky_linux | — | Upgrade wavpack-debugsourceUpgrade wavpackUpgrade wavpack-debuginfoUpgrade wavpack-devel | Mar 12, 2024 | Jul 11, 2019 |
| Ubuntu | — | Upgrade wavpackUpgrade libwavpack1 | Jul 17, 2019 | Jul 11, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub