CVE-2016-10169: Medium severity Wavpack Project Wavpack vulnerability
Last updated 25 August 2025
Other sources
The readcode function in readwords.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wavpackto a version that resolves this vulnerability.Fixed in 5.4.0-1Fixed in 5.6.0-1Fixed in 5.8.1-1Fixed in 5.9.0-2 - Upgrade
Upgrade
Wavpackto a version that resolves this vulnerability.Fixed in 5.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10169?
CVE-2016-10169 has been assessed as having a moderate severity level due to the potential for denial of service through out-of-bounds reads.
How do I fix CVE-2016-10169?
To fix CVE-2016-10169, update Wavpack to version 5.1.0 or later, which addresses the vulnerability.
Which versions of Wavpack are affected by CVE-2016-10169?
Wavpack versions prior to 5.1.0 are affected by CVE-2016-10169 and should be updated.
What type of attack does CVE-2016-10169 allow?
CVE-2016-10169 allows remote attackers to perform a denial of service attack through crafted WV files.
Is CVE-2016-10169 specific to any operating system?
CVE-2016-10169 affects Wavpack across multiple operating systems, including certain versions in Ubuntu and Debian.