wavpack: null pointer dereference in main() in cli/wvunpack.c
Published Jul 19, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.38%
Description
A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x561b47a970c6 bp 0x7fff13952fb0 sp 0x7fff1394fca0 T0) ==84257==The signal is caused by a WRITE memory access. ==84257==Hint: address points to the zero page. #0 0x561b47a970c5 in main cli/wvunpack.c:834 #1 0x7efc4f5c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) #2 0x561b47a945ed in _start (/usr/local/bin/wvunpack+0xa5ed) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV cli/wvunpack.c:834 in main ==84257==ABORTING
Affected products
- Vendor n/a Product Wavpack Defaultunknown
Affected
- 5.5.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Wavpack | unknown | Affected
|
Configuration 2
- 35
- 36
No data.
Red Hat Enterprise Linux 6
wavpack
Not affected
Red Hat Enterprise Linux 7
wavpack
Not affected
Red Hat Enterprise Linux 8
wavpack
Fix deferred
Red Hat Enterprise Linux 9
wavpack
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wavpack | Not affected | n/a |
| Red Hat Enterprise Linux 7 | wavpack | Not affected | n/a |
| Red Hat Enterprise Linux 8 | wavpack | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wavpack | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-2476 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2110455 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34735 Advisory
- https://github.com/dbry/WavPack/issues/121 ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CK45CC7MQ54SHEIJ63PW3HP4BCPTX6QP/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMIXZWB3OURGBAEU3T5HQY56BN2ZVLYF/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2476
- https://www.cve.org/CVERecord?id=CVE-2022-2476
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data