Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-19840
Description:The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2020.2727.1   1.3.6.1.4.1.25623.1.1.4.2019.13990.1   1.3.6.1.4.1.25623.1.1.2.2019.1901   1.3.6.1.4.1.25623.1.1.2.2019.1874  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-19840
Bugtraq: 20191219 [slackware-security] wavpack (SSA:2019-353-01) (Google Search)
https://seclists.org/bugtraq/2019/Dec/37
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZGXJUHCGQI6XKLCBUZHXPYIIWMFWA22/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WVVKOBJR5APOB3KWUWJ4UWQHUBZQL6C6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BLSOEVEKF4VNNVNZ2AN46BJUT4TGVWT/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BRWQNE3TH5UF64IKHKKHVCHJHUOVKJUH/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6CFFFWIWALGQPKINRDW3PRGRD5LOLGZA/
https://security.gentoo.org/glsa/202007-19
http://packetstormsecurity.com/files/155743/Slackware-Security-Advisory-wavpack-Updates.html
https://github.com/dbry/WavPack/commit/070ef6f138956d9ea9612e69586152339dbefe51
https://github.com/dbry/WavPack/issues/53
https://lists.debian.org/debian-lts-announce/2021/01/msg00013.html
SuSE Security Announcement: openSUSE-SU-2019:1145 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00029.html
https://usn.ubuntu.com/3839-1/




© 1998-2025 E-Soft Inc. All rights reserved.