Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19840

Опубликовано: 04 дек. 2018
Источник: debian
EPSS Низкий

Описание

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wavpackfixed5.1.0-5package

Примечания

  • https://github.com/dbry/WavPack/commit/070ef6f138956d9ea9612e69586152339dbefe51

  • https://github.com/dbry/WavPack/issues/53

EPSS

Процентиль: 57%
0.00353
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

CVSS3: 3.3
redhat
больше 6 лет назад

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

CVSS3: 5.5
nvd
больше 6 лет назад

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

suse-cvrf
почти 5 лет назад

Security update for wavpack

suse-cvrf
больше 6 лет назад

Security update for wavpack

EPSS

Процентиль: 57%
0.00353
Низкий