PT-2020-5481 · Wavpack+5 · Wavpack+5
Alexander Novikov
+9
·
Published
2020-12-27
·
Updated
2024-12-10
·
CVE-2020-35738
CVSS v2.0
7.8
High
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
WavPack versions 5.3.0 through 5.3.2
Description
The issue is related to an out-of-bounds write in the
WavpackPackSamples function in the pack utils.c file due to an integer overflow in a malloc argument. This can allow a remote attacker to compromise data integrity and cause a denial of service.Recommendations
For WavPack versions 5.3.0 through 5.3.2, consider disabling the
WavpackPackSamples function as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Integer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wavpack