wavpack-5.4.0-5.el9

エラータID: AXSA:2023-4610:01

Release date: 
Thursday, January 5, 2023 - 10:36
Subject: 
wavpack-5.4.0-5.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Low
Description: 

WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode.

Security Fix(es):

* wavpack: Heap out-of-bounds read in WavpackPackSamples() (CVE-2021-44269)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9.1 Release Notes linked from the References section.

CVE-2021-44269
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. wavpack-5.4.0-5.el9.src.rpm
    MD5: 34d4a8f18032ef9b9d655f0a37ddbe35
    SHA-256: 1aceba749aa8e0eae50616cc6b2c035183d6e59893994f0d7e2f80046670c5e9
    Size: 854.63 kB

Asianux Server 9 for x86_64
  1. wavpack-5.4.0-5.el9.x86_64.rpm
    MD5: 9b3fd2b275b7855464bb4282a14a5e6e
    SHA-256: 7a4adbd12e9855f87471275ba553f584ba1f7f7664046df36c2f5867fb254edc
    Size: 210.91 kB
  2. wavpack-devel-5.4.0-5.el9.x86_64.rpm
    MD5: e205d4534d0ba16839fe67b327061b0a
    SHA-256: 4e94699e11571999f6ec31cc18f5bb91817b37c81a0edda4ffc7e2d2571868d4
    Size: 320.33 kB
  3. wavpack-5.4.0-5.el9.i686.rpm
    MD5: 70effc8fb7821cacd674a0b2e87113e5
    SHA-256: ad41ccc972d89e9b4fda86626c9aa365a01915dcf431c296977b4f6212af553e
    Size: 224.11 kB
  4. wavpack-devel-5.4.0-5.el9.i686.rpm
    MD5: 284ff07ab3bc296b46eefa36eab0532c
    SHA-256: c879e54cbede5611dca33883e09f33ccd19471ee456df9f98b8028e275c57057
    Size: 320.34 kB