The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
{ "vanir_signatures": [ { "id": "CVE-2016-10170-8ae8fa06", "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "258850288732523643512675473133534382534", "220347052653996422538150640887459021458", "164662209618117995073184152411630754512", "229981819128427362146009415295274641495", "185889359717517232897891319245691122292", "331743087455671763299233936012568132181", "25564655387442595063734045720924497048", "144707297014856422073319844326463066547" ] }, "target": { "file": "src/open_utils.c" } }, { "id": "CVE-2016-10170-bcd82de9", "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "220368600512407806609558388534790306706", "308456421510775067050619380014020586139", "117541840331745660331830910238677499720", "283477992805437530837810981096645513154" ] }, "target": { "file": "src/read_words.c" } }, { "id": "CVE-2016-10170-ebcacf67", "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 5248.0, "function_hash": "164253035093328456349796014300482149401" }, "target": { "file": "src/read_words.c", "function": "get_word" } }, { "id": "CVE-2016-10170-ec847c9e", "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 1030.0, "function_hash": "336068580949872724902448003637322357508" }, "target": { "file": "src/open_utils.c", "function": "read_new_config_info" } } ] }