An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/dbry/WavPack/issues/32 | issue tracking third party advisory |
https://www.debian.org/security/2018/dsa-4197 | third party advisory vendor advisory |
https://github.com/dbry/WavPack/issues/31 | issue tracking third party advisory |
https://usn.ubuntu.com/3637-1/ | third party advisory vendor advisory |
https://github.com/dbry/WavPack/issues/30 | issue tracking third party advisory |
https://github.com/dbry/WavPack/commit/26cb47f99d481ad9b93eeff80d26e6b63bbd7e15 | third party advisory patch |
https://seclists.org/bugtraq/2019/Dec/37 | mailing list |
http://packetstormsecurity.com/files/155743/Slackware-Security-Advisory-wavpack-Updates.html | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CFFFWIWALGQPKINRDW3PRGRD5LOLGZA/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRWQNE3TH5UF64IKHKKHVCHJHUOVKJUH/ | vendor advisory |