An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.
{ "binaries": [ { "binary_name": "libwavpack-dev", "binary_version": "5.1.0-2ubuntu1.5" }, { "binary_name": "libwavpack1", "binary_version": "5.1.0-2ubuntu1.5" }, { "binary_name": "wavpack", "binary_version": "5.1.0-2ubuntu1.5" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44269.json"
{ "binaries": [ { "binary_name": "libwavpack-dev", "binary_version": "5.2.0-1ubuntu0.1" }, { "binary_name": "libwavpack1", "binary_version": "5.2.0-1ubuntu0.1" }, { "binary_name": "wavpack", "binary_version": "5.2.0-1ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "libwavpack-dev", "binary_version": "5.4.0-1build2" }, { "binary_name": "libwavpack1", "binary_version": "5.4.0-1build2" }, { "binary_name": "wavpack", "binary_version": "5.4.0-1build2" } ] }
{ "binaries": [ { "binary_name": "libwavpack-dev", "binary_version": "5.6.0-1build1" }, { "binary_name": "libwavpack1", "binary_version": "5.6.0-1build1" }, { "binary_name": "wavpack", "binary_version": "5.6.0-1build1" } ] }
{ "binaries": [ { "binary_name": "libwavpack-dev", "binary_version": "5.8.1-1" }, { "binary_name": "libwavpack1", "binary_version": "5.8.1-1" }, { "binary_name": "wavpack", "binary_version": "5.8.1-1" } ] }