CVE-2018-10537: Buffer Overflow
Published Apr 29, 2018
·Updated
An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks.
Affected Software
4 affected componentsFixes available
WavPack Wavpack<=5.1.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/wavpack
5.4.0-15.6.0-15.8.1-15.9.0-1
Remediation
Event History
Apr 29, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·03:53 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:54 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10537?
CVE-2018-10537 has a high severity rating due to the potential for memory corruption vulnerabilities.
2
How do I fix CVE-2018-10537?
To fix CVE-2018-10537, upgrade to WavPack version 5.4.0 or later.
3
Which versions of WavPack are affected by CVE-2018-10537?
WavPack versions 5.1.0 and earlier are affected by CVE-2018-10537.
4
Are there specific distributions affected by CVE-2018-10537?
Yes, Debian 8.0, Debian 9.0, and certain Ubuntu versions are affected due to the vulnerable WavPack package.
5
What type of vulnerability is CVE-2018-10537 classified as?
CVE-2018-10537 is classified as a memory corruption vulnerability affecting the W64 parser component of WavPack.