CVE-2016-10170

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-10170
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10170.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-10170
Downstream
Related
Published
2017-03-14T14:59:00Z
Modified
2025-10-13T05:35:34.609731Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

References

Affected packages

Git / github.com/dbry/wavpack

Affected ranges

Type
GIT
Repo
https://github.com/dbry/wavpack
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

4.*

4.70.0
4.70.0-rc
4.75.0
4.75.0-rc
4.75.2
4.80.0
4.80.0-rc

5.*

5.0.0
5.0.0-alpha
5.0.0-alpha2
5.0.0-alpha3
5.0.0-alpha4
5.0.0-alpha5

Database specific

{
    "vanir_signatures": [
        {
            "id": "CVE-2016-10170-8ae8fa06",
            "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Line",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "258850288732523643512675473133534382534",
                    "220347052653996422538150640887459021458",
                    "164662209618117995073184152411630754512",
                    "229981819128427362146009415295274641495",
                    "185889359717517232897891319245691122292",
                    "331743087455671763299233936012568132181",
                    "25564655387442595063734045720924497048",
                    "144707297014856422073319844326463066547"
                ]
            },
            "target": {
                "file": "src/open_utils.c"
            }
        },
        {
            "id": "CVE-2016-10170-bcd82de9",
            "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Line",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "220368600512407806609558388534790306706",
                    "308456421510775067050619380014020586139",
                    "117541840331745660331830910238677499720",
                    "283477992805437530837810981096645513154"
                ]
            },
            "target": {
                "file": "src/read_words.c"
            }
        },
        {
            "id": "CVE-2016-10170-ebcacf67",
            "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Function",
            "digest": {
                "length": 5248.0,
                "function_hash": "164253035093328456349796014300482149401"
            },
            "target": {
                "file": "src/read_words.c",
                "function": "get_word"
            }
        },
        {
            "id": "CVE-2016-10170-ec847c9e",
            "source": "https://github.com/dbry/wavpack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Function",
            "digest": {
                "length": 1030.0,
                "function_hash": "336068580949872724902448003637322357508"
            },
            "target": {
                "file": "src/open_utils.c",
                "function": "read_new_config_info"
            }
        }
    ]
}