wavpack
Link | package | bugs open | bugs closed | Wiki | GitHub | web search |
Description | Audio compression format with lossless, lossy and hybrid compression modes |
Version | 5.7.0-1 [extra] |
Resolved
Group | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|
AVG-1387 | 5.3.0-1 | 5.3.0-2 | Medium | Fixed | FS#69234 |
AVG-631 | 4.80.0-1 | 5.1.0-2 | High | Fixed | FS#57609 |
Issue | Group | Severity | Remote | Type | Description |
---|---|---|---|---|---|
CVE-2020-35738 | AVG-1387 | Medium | No | Arbitrary code execution | WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. |
CVE-2018-7254 | AVG-631 | Medium | Yes | Arbitrary code execution | The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read),... |
CVE-2018-7253 | AVG-631 | High | Yes | Arbitrary code execution | The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer... |
CVE-2018-6767 | AVG-631 | Medium | Yes | Arbitrary code execution | A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a... |
Advisories
Date | Advisory | Group | Severity | Type |
---|---|---|---|---|
12 Jan 2021 | ASA-202101-23 | AVG-1387 | Medium | arbitrary code execution |
23 Feb 2018 | ASA-201802-12 | AVG-631 | High | arbitrary code execution |