Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-7254Out-of-bounds Read in Wavpack

Severity
7.8HIGHNVD
EPSS
21.3%
top 4.30%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 19
Latest updateMay 13

Description

The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafted CAF file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

debiandebian/wavpack< wavpack 5.1.0-3 (bookworm)
Debianwavpack/wavpack< 5.1.0-3+3
NVDwavpack/wavpack5.1.0

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-57rx-55jg-62vm: The ParseCaffHeaderConfig function of the cli/caff2022-05-13
OSV
CVE-2018-7254: The ParseCaffHeaderConfig function of the cli/caff2018-02-19

💥Exploits & PoCs

3
Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal2019-11-12
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation2019-11-12
Exploit-DB
Wavpack 5.1.0 - Denial of Service2018-02-21

📋Vendor Advisories

3
Ubuntu
WavPack vulnerabilities2018-02-22
Red Hat
wavpack: Global buffer over-read in ParseCaffHeaderConfig function in cli/caff.c2018-02-19
Debian
CVE-2018-7254: wavpack - The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allow...2018

💬Community

4
Bugzilla
CVE-2018-7254 mingw-wavpack: wavpack: Heap-based buffer over-read in ParseCaffHeaderConfig function in cli/caff.c [epel-7]2018-02-21
Bugzilla
CVE-2018-7254 mingw-wavpack: wavpack: Heap-based buffer over-read in ParseCaffHeaderConfig function in cli/caff.c [fedora-all]2018-02-21
Bugzilla
CVE-2018-7254 wavpack: Global buffer over-read in ParseCaffHeaderConfig function in cli/caff.c2018-02-21
Bugzilla
CVE-2018-7254 wavpack: Heap-based buffer over-read in ParseCaffHeaderConfig function in cli/caff.c [fedora-all]2018-02-21