Heap-based buffer overwrite in WavPack - CVE-2018-10537
Published: May 8, 2018 / Updated: May 8, 2018
Vulnerability identifier: #VU12399
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10537
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition or execute arbitrary code on the target system.
The weakness exists in the W64 parser component due to improper rejection of multiple format chunks by the ParseWave64HeaderConfig function, as defined in the wave64.c source code file. A local attacker can execute a specially crafted .wav file, trigger heap buffer overwrite and cause the service to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists in the W64 parser component due to improper rejection of multiple format chunks by the ParseWave64HeaderConfig function, as defined in the wave64.c source code file. A local attacker can execute a specially crafted .wav file, trigger heap buffer overwrite and cause the service to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
WavPack
Debian Linux
Fedora
Slackware Linux
wavpack (Alpine package)
wavpack
mingw-wavpack
Debian Linux
Fedora
Slackware Linux
wavpack (Alpine package)
wavpack
mingw-wavpack
How to mitigate CVE-2018-10537
Install update from vendor's website.
wavpack (Alpine package) - addressed in versions 5.1.0-r2, 5.1.0-r6
wavpack - addressed in versions 5.1.0-8.fc27, 5.1.0-8.fc28
mingw-wavpack - addressed in versions 5.1.0-9.el7, 5.1.0-9.fc30, 5.1.0-9.fc31
wavpack - addressed in versions 5.1.0-8.fc27, 5.1.0-8.fc28
mingw-wavpack - addressed in versions 5.1.0-9.el7, 5.1.0-9.fc30, 5.1.0-9.fc31
External References
Related Security Bulletins
- Remote code execution in WavPack
- Debian update for wavpack
- Slackware Linux update for wavpack
- Heap-based buffer overwrite in wavpack (Alpine package)
- Fedora 27 update for wavpack
- Fedora 28 update for wavpack
- Fedora EPEL 7 update for mingw-wavpack
- Fedora 31 update for mingw-wavpack
- Fedora 30 update for mingw-wavpack