CVE-2018-19840: Medium severity WavPack Wavpack vulnerability
Last updated 25 August 2025
Other sources
The function WavpackPackInit in packutils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19840?
CVE-2018-19840 has a high severity rating due to the potential for denial-of-service attacks caused by resource exhaustion.
How do I fix CVE-2018-19840?
To fix CVE-2018-19840, upgrade to WavPack versions 5.4.0 or higher.
What causes the vulnerability in CVE-2018-19840?
CVE-2018-19840 is caused by an infinite loop triggered by a malformed WAV audio file in the Wavpack library.
Which software versions are affected by CVE-2018-19840?
Affected versions for CVE-2018-19840 include WavPack versions up to 5.1.0.
How can attackers exploit CVE-2018-19840?
Attackers can exploit CVE-2018-19840 by providing a specially crafted WAV audio file that leads to a denial-of-service condition.