An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks.
References
Configurations
History
No history.
Information
Published : 2018-04-29 15:29
Updated : 2024-11-21 03:41
NVD link : CVE-2018-10537
Mitre link : CVE-2018-10537
CVE.ORG link : CVE-2018-10537
JSON object : View
Products Affected
debian
- debian_linux
wavpack
- wavpack
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer