WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
References
Link | Resource |
---|---|
https://github.com/dbry/WavPack/issues/91 | Exploit Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/01/msg00013.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2YZLKYE66EU4XRHTABV5LB2G7ZDZ422F/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PENN4ZXRPZULEJOYTTLUZMBZ5H46QTUC/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDFY4NGGDUTLVID5PNVU7LL2G2ZJLZFY/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/76B7K6F74FDQATG7FECXR5KPIG52O2VL/ | Mailing List Third Party Advisory |
Information
Published : 2020-12-27 20:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-35738
Mitre link : CVE-2020-35738
JSON object : View
Products Affected
debian
- debian_linux
fedoraproject
- fedora
wavpack
- wavpack