Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-35738

Опубликовано: 28 дек. 2020
Источник: debian

Описание

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wavpackfixed5.3.0-2package
wavpackno-dsabusterpackage

Примечания

  • https://github.com/dbry/WavPack/issues/91

  • https://github.com/dbry/WavPack/commit/63f3ec70129843dd64e11aa4c21c4a1cf00c9f1c

  • https://github.com/dbry/WavPack/commit/89df160596132e3bd666322e1c20b2ebd4b92cd0

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

CVSS3: 6.1
redhat
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

CVSS3: 6.1
nvd
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

suse-cvrf
почти 5 лет назад

Security update for wavpack

suse-cvrf
почти 5 лет назад

Security update for wavpack