CVE-2018-19841: Medium severity WavPack Wavpack vulnerability
Last updated 25 August 2025
Other sources
The function WavpackVerifySingleBlock in openutils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19841?
CVE-2018-19841 has a severity rating that indicates it can lead to a denial of service due to an out-of-bounds read and application crash.
How do I fix CVE-2018-19841?
To fix CVE-2018-19841, upgrade WavPack to versions 5.4.0-1 or higher, specifically 5.6.0-1 or 5.7.0-1.
Which software versions are affected by CVE-2018-19841?
CVE-2018-19841 affects all versions of WavPack up to and including 5.1.0.
What impact can CVE-2018-19841 have on my system?
CVE-2018-19841 can result in a denial-of-service attack, causing applications that utilize WavPack to crash when processing specially crafted audio files.
Are there any operating systems that need to be addressed for CVE-2018-19841?
Yes, CVE-2018-19841 affects multiple operating systems including various versions of Debian, Ubuntu, Fedora, and openSUSE.