4.3
CVSSv2

CVE-2019-1010315

Published: 11/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

WavPack 5.1 and previous versions is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (dsdiff.c:282). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit github.com/dbry/WavPack/commit/4c0faba32fddbd0745cbfaf1e1aeb3da5d35b9fc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wavpack wavpack

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 9.0

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

Vendor Advisories

WavPack could be made to crash if it received a specially crafted WAV file ...
Impact: Moderate Public Date: 2019-07-12 CWE: CWE-369 Bugzilla: 1729418: CVE-2019-1010315 WavPack: divi ...