Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pwmw-jmr6-f7c4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

EPSS

Процентиль: 61%
0.00408
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

CVSS3: 6.1
redhat
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

CVSS3: 6.1
nvd
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

CVSS3: 6.1
debian
около 5 лет назад

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack ...

suse-cvrf
почти 5 лет назад

Security update for wavpack

EPSS

Процентиль: 61%
0.00408
Низкий

Дефекты

CWE-787