Out-of-bounds read in WavPack - CVE-2021-44269

 

Out-of-bounds read in WavPack - CVE-2021-44269

Published: July 11, 2022


Vulnerability identifier: #VU65086
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44269
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition when processing *.WAV files within the WavpackPackSamples() function in src/pack_utils.c. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and crash the application.


Affected software

WavPack
Oracle Linux
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Slackware Linux
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
Fedora
wavpack (Red Hat package)
libwavpack1
libwavpack1-debuginfo
wavpack
wavpack-debuginfo
wavpack-debugsource
wavpack-devel
mingw-wavpack
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2021-44269

Install updates from vendor's website.

WavPack - update to 5.5.0
wavpack (Red Hat package) - addressed in versions 5.1.0-16.el8, 5.4.0-5.el9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
libwavpack1 - update to 5.4.0-4.12.1
libwavpack1-debuginfo - update to 5.4.0-4.12.1
wavpack - update to 5.4.0-4.12.1
wavpack-debuginfo - update to 5.4.0-4.12.1
wavpack-debugsource - update to 5.4.0-4.12.1
wavpack-devel - update to 5.4.0-4.12.1
wavpack - addressed in versions 5.4.0-5.fc34, 5.4.0-5.fc35, 5.4.0-5.fc36
mingw-wavpack - addressed in versions 5.4.0-5.fc35, 5.4.0-5.fc36

External References

Related Security Bulletins