FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

wavpack -- multiple invalid memory reads

Affected packages
wavpack < 5.1.0

Details

VuXML ID f1075415-f5e9-11e6-a4e2-5404a68ad561
Discovery 2017-01-21
Entry 2017-02-18

David Bryant reports:

global buffer overread in read_code / read_words.c

heap out of bounds read in WriteCaffHeader / caff.c

heap out of bounds read in unreorder_channels / wvunpack.c

heap oob read in read_new_config_info / open_utils.c

References

CVE Name CVE-2016-10169
CVE Name CVE-2016-10170
CVE Name CVE-2016-10171
CVE Name CVE-2016-10172
URL http://www.openwall.com/lists/oss-security/2017/01/23/4
URL https://github.com/dbry/WavPack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc