Integer overflow in WavPack - CVE-2020-35738

 

Integer overflow in WavPack - CVE-2020-35738

Published: December 28, 2020 / Updated: December 29, 2020


Vulnerability identifier: #VU49197
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35738
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in WavpackPackSamples in pack_utils. A remote attacker can pass specially crafted file, trick the victim into opening it, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

WavPack
Arch Linux
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
openEuler
Fedora
wavpack (Alpine package)
libwavpack1
wavpack-debuginfo
wavpack-debugsource
wavpack-devel
libwavpack1-debuginfo
wavpack
wavpack (Ubuntu package)
wavpack-help
mingw-wavpack

How to mitigate CVE-2020-35738

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

wavpack (Alpine package) - update to 5.4.0-r0
libwavpack1 - addressed in versions 4.50.1-1.33.1, 4.60.99-5.9.1
wavpack-debuginfo - addressed in versions 4.50.1-1.33.1, 4.60.99-5.9.1
wavpack-debugsource - addressed in versions 4.50.1-1.33.1, 4.60.99-5.9.1
wavpack-devel - update to 4.60.99-5.9.1
libwavpack1-debuginfo - update to 4.60.99-5.9.1
wavpack - update to 4.60.99-5.9.1
wavpack (Ubuntu package) - addressed in versions 5.1.0-2ubuntu1.5, 5.2.0-1ubuntu0.1, 5.3.0-1ubuntu0.1
wavpack - update to 5.3.0-2
wavpack-debuginfo - update to 5.3.0-2
wavpack-devel - update to 5.3.0-2
wavpack-debugsource - update to 5.3.0-2
wavpack-help - update to 5.3.0-2
wavpack - addressed in versions 5.4.0-1.fc32, 5.4.0-1.fc33
mingw-wavpack - addressed in versions 5.4.0-1.fc32, 5.4.0-1.fc33

External References

Related Security Bulletins