Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-44269

Опубликовано: 10 мар. 2022
Источник: debian
EPSS Низкий

Описание

An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wavpackfixed5.5.0-1package

Примечания

  • https://github.com/dbry/WavPack/issues/110

  • Fixed by: https://github.com/dbry/WavPack/commit/773f9d0803c6888ae7d5391878d7337f24216f4a

  • Negligible security impact; only impacts the CLI program

EPSS

Процентиль: 20%
0.00064
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

CVSS3: 3.5
redhat
больше 3 лет назад

An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

CVSS3: 5.5
nvd
больше 3 лет назад

An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

suse-cvrf
больше 3 лет назад

Security update for wavpack

suse-cvrf
больше 3 лет назад

Security update for wavpack

EPSS

Процентиль: 20%
0.00064
Низкий