漏洞信息详情

WavPack 安全漏洞

  • CNNVD编号:CNNVD-201812-074
  • 危害等级: 中危
  • CVE编号: CVE-2018-19841
  • 漏洞类型: 缓冲区错误
  • 发布时间: 2018-12-05
  • 威胁类型: 本地
  • 更新时间: 2021-01-25
  • 厂        商: canonical
  • 漏洞来源: Red Hat,Slackware ...

漏洞简介

WavPack是一套开源的、免费的音频无损压缩软件。

WavPack 5.1.0及之前版本中的libwavpack.a静态链接库的open_utils.c文件‘WavpackVerifySingleBlock’函数存在安全漏洞。攻击者可借助特制的WavPack Lossless Audio文件利用该漏洞造成拒绝服务(越界读取和应用程序崩溃)。

漏洞公告

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

https://github.com/dbry/WavPack/commit/bba5389dc598a92bdf2b297c3ea34620b6679b5b

参考网址

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BRWQNE3TH5UF64IKHKKHVCHJHUOVKJUH/

来源:GENTOO

链接:https://security.gentoo.org/glsa/202007-19

来源:MISC

链接:https://github.com/dbry/WavPack/issues/54

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BLSOEVEKF4VNNVNZ2AN46BJUT4TGVWT/

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00029.html

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CFFFWIWALGQPKINRDW3PRGRD5LOLGZA/

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2021/01/msg00013.html

来源:UBUNTU

链接:https://usn.ubuntu.com/3839-1/

来源:BUGTRAQ

链接:https://seclists.org/bugtraq/2019/Dec/37

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WVVKOBJR5APOB3KWUWJ4UWQHUBZQL6C6/

来源:MISC

链接:https://packetstormsecurity.com/files/155743/Slackware-Security-Advisory-wavpack-Updates.html

来源:FEDORA

链接:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZGXJUHCGQI6XKLCBUZHXPYIIWMFWA22/

来源:MISC

链接:https://github.com/dbry/WavPack/commit/bba5389dc598a92bdf2b297c3ea34620b6679b5b

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-201913992-1.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.0195/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1522/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/77938

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/155743/Slackware-Security-Advisory-wavpack-Updates.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2021.0278/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/157449/Red-Hat-Security-Advisory-2020-1581-01.html

漏洞信息快速查询

相关漏洞

更多