漏洞信息详情
WavPack 缓冲区错误漏洞
漏洞简介
WavPack是一套开源的、免费的音频无损压缩软件。
WavPack 5.3.0 存在缓冲区错误漏洞,该漏洞源于malloc参数中有一个整数溢出。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/dbry/WavPack/commit/940a8b7f35205efbd5d64a88875481a7dbfa7e52
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/2YZLKYE66EU4XRHTABV5LB2G7ZDZ422F/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/PENN4ZXRPZULEJOYTTLUZMBZ5H46QTUC/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/01/msg00013.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/76B7K6F74FDQATG7FECXR5KPIG52O2VL/
来源:MISC
链接:https://github.com/dbry/WavPack/issues/91
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/VDFY4NGGDUTLVID5PNVU7LL2G2ZJLZFY/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0195/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1011
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0062/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0278/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-35738
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/WavPack-integer-overflow-via-WavpackPackSamples-34249
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0989
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160827/Ubuntu-Security-Notice-USN-4682-1.html
受影响实体
暂无
补丁
- WavPack 缓冲区错误漏洞的修复措施<!--2020-12-27-->
还没有评论,来说两句吧...