4.3
CVSSv2

CVE-2021-44269

Published: 10/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A heap out-of-bounds read flaw was found in WavPacks' WavpackPackSamples() function of src/pack_utils.c and only affects the command-line program of WavPack (not libwavpack). This flaw allows an malicious user to exploit this flaw for a website that uses the WavPack command-line program on user-provided files, causing a denial of service. (CVE-2021-44269)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wavpack wavpack 5.4.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Synopsis Low: wavpack security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for wavpack is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security imp ...
Synopsis Low: wavpack security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for wavpack is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security imp ...
A heap out-of-bounds read flaw was found in WavPacks' WavpackPackSamples() function of src/pack_utilsc and only affects the command-line program of WavPack (not libwavpack) This flaw allows an attacker to exploit this flaw for a website that uses the WavPack command-line program on user-provided files, causing a denial of service (CVE-2021-44269 ...