4.3
CVSSv2

CVE-2018-19840

Published: 04/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack up to and including 5.1.0 allows malicious users to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wavpack wavpack

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

fedoraproject fedora 28

fedoraproject fedora 29

fedoraproject fedora 30

opensuse leap 15.0

Vendor Advisories

Several security issues were fixed in WavPack ...
Debian Bug report logs - #915564 wavpack: CVE-2018-19840: Infinite loop when block_samples==0 using wavpack Package: src:wavpack; Maintainer for src:wavpack is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Dec 2018 21:15:02 UTC ...
Debian Bug report logs - #915565 wavpack: CVE-2018-19841: heap-buffer-overflow Package: src:wavpack; Maintainer for src:wavpack is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Dec 2018 21:15:06 UTC Severity: important Tags: pat ...