The readcode function in readwords.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
[
{
"id": "CVE-2016-10169-8ae8fa06",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"258850288732523643512675473133534382534",
"220347052653996422538150640887459021458",
"164662209618117995073184152411630754512",
"229981819128427362146009415295274641495",
"185889359717517232897891319245691122292",
"331743087455671763299233936012568132181",
"25564655387442595063734045720924497048",
"144707297014856422073319844326463066547"
],
"threshold": 0.9
},
"target": {
"file": "src/open_utils.c"
},
"signature_type": "Line",
"source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc"
},
{
"id": "CVE-2016-10169-bcd82de9",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"220368600512407806609558388534790306706",
"308456421510775067050619380014020586139",
"117541840331745660331830910238677499720",
"283477992805437530837810981096645513154"
],
"threshold": 0.9
},
"target": {
"file": "src/read_words.c"
},
"signature_type": "Line",
"source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc"
},
{
"id": "CVE-2016-10169-ebcacf67",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 5248.0,
"function_hash": "164253035093328456349796014300482149401"
},
"target": {
"function": "get_word",
"file": "src/read_words.c"
},
"signature_type": "Function",
"source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc"
},
{
"id": "CVE-2016-10169-ec847c9e",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1030.0,
"function_hash": "336068580949872724902448003637322357508"
},
"target": {
"function": "read_new_config_info",
"file": "src/open_utils.c"
},
"signature_type": "Function",
"source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc"
}
]