4.3
CVSSv2

CVE-2018-19841

Published: 04/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack up to and including 5.1.0 allows malicious users to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wavpack wavpack

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

fedoraproject fedora 28

fedoraproject fedora 29

fedoraproject fedora 30

fedoraproject fedora 31

opensuse leap 15.0

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in WavPack ...
Debian Bug report logs - #915564 wavpack: CVE-2018-19840: Infinite loop when block_samples==0 using wavpack Package: src:wavpack; Maintainer for src:wavpack is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Dec 2018 21:15:02 UTC ...
Debian Bug report logs - #915565 wavpack: CVE-2018-19841: heap-buffer-overflow Package: src:wavpack; Maintainer for src:wavpack is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Dec 2018 21:15:06 UTC Severity: important Tags: pat ...
The function WavpackVerifySingleBlock in open_utilsc in libwavpacka in WavPack through 510 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack ...