CVE-2020-35738: Integer Overflow
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in packutils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35738?
CVE-2020-35738 is considered a high-severity vulnerability due to its potential for causing out-of-bounds write conditions.
How do I fix CVE-2020-35738?
To fix CVE-2020-35738, you should update WavPack to version 5.3.2 or later, if applicable.
Which versions of WavPack are affected by CVE-2020-35738?
CVE-2020-35738 affects WavPack version 5.3.0 and may also impact unofficial releases through version 5.3.2.
What are the consequences of exploiting CVE-2020-35738?
Exploitation of CVE-2020-35738 could lead to arbitrary code execution or application crashes due to memory corruption.
Which operating systems are vulnerable to CVE-2020-35738?
CVE-2020-35738 affects WavPack on various operating systems including Debian 9.0 and Fedora versions 32 and 33.