Description
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2525-1 | wavpack security update |
EUVD |
EUVD-2018-11516 | The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack. |
Ubuntu USN |
USN-3839-1 | WavPack vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:44:20.579Z
Reserved: 2018-12-03T00:00:00.000Z
Link: CVE-2018-19841
No data.
Status : Modified
Published: 2018-12-04T09:29:00.663
Modified: 2024-11-21T03:58:40.290
Link: CVE-2018-19841
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN