Red Hat Bugzilla – Bug 1574719
CVE-2018-10536 wavpack: out of bounds write in ParseRiffHeaderConfig in riff.c
Last modified: 2018-07-26 23:23:46 EDT
An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks. References: https://github.com/dbry/WavPack/issues/30 https://github.com/dbry/WavPack/issues/31 https://github.com/dbry/WavPack/issues/32 Patch: https://github.com/dbry/WavPack/commit/26cb47f99d481ad9b93eeff80d26e6b63bbd7e15
Created mingw-wavpack tracking bugs for this issue: Affects: epel-7 [bug 1574720] Affects: fedora-all [bug 1574723] Created wavpack tracking bugs for this issue: Affects: fedora-all [bug 1574721]
The affected chunk of code in wavpack prior to 4.80 is in cli/wavpack.c; see also bug 1574728
Statement: Red Hat Enterprise Linux 6 is now in Maintenance support 2 Phase of the support and maintenance life cycle. This issue has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/