Описание
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
Меры по смягчению последствий
If using the wavpack utility, this flaw can be mitigated by not running the program on untrusted input files or files from untrusted sources.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | wavpack | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wavpack | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wavpack | Will not fix | ||
| Red Hat Enterprise Linux 9 | wavpack | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack ...
EPSS
6.1 Medium
CVSS3