vendor:
Wavpack
by:
r4xis
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Wavpack
Affected Version From: 5.1.0
Affected Version To: 5.1.0
Patch Exists: YES
Related CWE: CVE-2018-7254
CPE: a:wavpack:wavpack:5.1.0
Metasploit:
https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-7254/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2018-7254/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-7254/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-7254/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-7254/
Other Scripts:
N/A
Platforms Tested: Debian 9.3.0 64 bit, Windows 7 32 bit and 64 bit, Windows 8 64 bit
2018
Wavpack 5.1.0 – Denial of Service
A denial of service vulnerability exists in Wavpack 5.1.0 when a specially crafted .caf file is processed, which could allow an attacker to cause a denial of service condition. This is due to a memmove_sse2_unaligned_erms() function call in the wvunpack.c file, which can be triggered by a crafted .caf file. This issue is related to CVE-2018-7254.
Mitigation:
Upgrade to Wavpack 5.1.1 or later.