|Description||An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)|
Vulnerable and fixed packages
The table below lists information on source packages.
|sid, trixie, bookworm||5.6.0-1||fixed|
The information below is based on the following data on fixed versions.
[jessie] - wavpack <not-affected> (Vulnerable code not present, introduced in 5.0.0)
[wheezy] - wavpack <not-affected> (Vulnerable code not present, introduced in 5.0.0)