The readnewconfiginfo function in openutils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
[ { "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "target": { "file": "src/open_utils.c" }, "id": "CVE-2016-10172-8ae8fa06", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "digest": { "line_hashes": [ "258850288732523643512675473133534382534", "220347052653996422538150640887459021458", "164662209618117995073184152411630754512", "229981819128427362146009415295274641495", "185889359717517232897891319245691122292", "331743087455671763299233936012568132181", "25564655387442595063734045720924497048", "144707297014856422073319844326463066547" ], "threshold": 0.9 } }, { "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "target": { "file": "src/read_words.c" }, "id": "CVE-2016-10172-bcd82de9", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "digest": { "line_hashes": [ "220368600512407806609558388534790306706", "308456421510775067050619380014020586139", "117541840331745660331830910238677499720", "283477992805437530837810981096645513154" ], "threshold": 0.9 } }, { "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "target": { "function": "get_word", "file": "src/read_words.c" }, "id": "CVE-2016-10172-ebcacf67", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "digest": { "function_hash": "164253035093328456349796014300482149401", "length": 5248.0 } }, { "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "target": { "function": "read_new_config_info", "file": "src/open_utils.c" }, "id": "CVE-2016-10172-ec847c9e", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "digest": { "function_hash": "336068580949872724902448003637322357508", "length": 1030.0 } } ]