Out-of-bounds read in WavPack - CVE-2021-44269
Published: July 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing *.WAV files within the WavpackPackSamples() function in src/pack_utils.c. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and crash the application.
Affected software
Oracle Linux
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Slackware Linux
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
Fedora
wavpack (Red Hat package)
libwavpack1
libwavpack1-debuginfo
wavpack
wavpack-debuginfo
wavpack-debugsource
wavpack-devel
mingw-wavpack
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2021-44269
wavpack (Red Hat package) - addressed in versions 5.1.0-16.el8, 5.4.0-5.el9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
libwavpack1 - update to 5.4.0-4.12.1
libwavpack1-debuginfo - update to 5.4.0-4.12.1
wavpack - update to 5.4.0-4.12.1
wavpack-debuginfo - update to 5.4.0-4.12.1
wavpack-debugsource - update to 5.4.0-4.12.1
wavpack-devel - update to 5.4.0-4.12.1
wavpack - addressed in versions 5.4.0-5.fc34, 5.4.0-5.fc35, 5.4.0-5.fc36
mingw-wavpack - addressed in versions 5.4.0-5.fc35, 5.4.0-5.fc36
External References
- https://github.com/dbry/WavPack/issues/110
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CRZWZKEEABCLVXZEXQZBIT3ZKLIXVFF5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2CZUFTX3J4Y4OSRITG4PXCI7NRVFDYVQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQKOOJRI2VAPYS3652HVDXON723HTXBP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A5B7L26LA6KGX7YH6SWD5CSBNWKV5MBO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I54NXQZELBF42OL4KQZJJRAYZX7IPZXP/
Related Security Bulletins
- Denial of service in Wavpack
- Slackware Linux update for wavpack
- Red Hat Enterprise Linux 8 update for wavpack
- Red Hat Enterprise Linux 9 update for wavpack
- SUSE update for wavpack
- Out-of-bounds read in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Oracle Linux
- Fedora 34 update for wavpack
- Fedora 35 update for wavpack
- Fedora 36 update for wavpack
- Fedora 36 update for mingw-wavpack
- Fedora 35 update for mingw-wavpack