
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-44269 affects WavPack version 5.4.0, an open audio compression format software. The vulnerability was discovered in the WavpackPackSamples function within src/pack_utils.c, where an out-of-bounds read vulnerability exists when processing WAV files (NVD, GitHub Issue).
The vulnerability occurs in the WavpackPackSamples function in src/pack_utils.c. The issue arises when the variable 'cnt' becomes too large, causing the pointer 'sptr' to read beyond heap boundaries. This happens specifically in the code block between lines 628-636 when processing mono flag operations (GitHub Issue).
The vulnerability allows for a heap out-of-bounds read condition when processing WAV files. This could potentially lead to information disclosure or application crashes (Red Hat).
Updates have been released to address this vulnerability. Red Hat has released security updates for affected versions in RHEL 8 and RHEL 9 systems. Fedora has also released patches for versions 34, 35, and 36 (Red Hat, Fedora).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."