PT-2020-5481 · Wavpack+5 · Wavpack+5

Alexander Novikov

+9

·

Published

2020-12-27

·

Updated

2024-12-10

·

CVE-2020-35738

CVSS v2.0

7.8

High

VectorAV:N/AC:M/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions WavPack versions 5.3.0 through 5.3.2
Description The issue is related to an out-of-bounds write in the WavpackPackSamples function in the pack utils.c file due to an integer overflow in a malloc argument. This can allow a remote attacker to compromise data integrity and cause a denial of service.
Recommendations For WavPack versions 5.3.0 through 5.3.2, consider disabling the WavpackPackSamples function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1214
BDU:2021-00777
CVE-2020-35738
DLA-2525-1
MGASA-2021-0271
OESA-2021-1131
OPENSUSE-SU-2021:0153-1
OPENSUSE-SU-2021:0154-1
OPENSUSE-SU-2021_0153-1
OPENSUSE-SU-2021_0154-1
OPENSUSE-SU-2024:11505-1
ROSA-SA-2024-2540
SUSE-SU-2021:0186-1
SUSE-SU-2021:0929-1
SUSE-SU-2021:14669-1
SUSE-SU-2021_0929-1
SUSE-SU-2021_14669-1
USN-4682-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wavpack