CVE-2019-1010317: Medium severity WavPack Wavpack vulnerability
Last updated 25 August 2025
Other sources
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/f68a9555b548306c5b1ee45199ccdc4a16a6101b.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010317?
CVE-2019-1010317 has a high severity due to the potential for unexpected control flow, crashes, and segmentation faults.
How do I fix CVE-2019-1010317?
To fix CVE-2019-1010317, update WavPack to version 5.1.0-2ubuntu1.4 or later on Ubuntu, or to versions 5.4.0-1, 5.6.0-1, or 5.7.0-1 on Debian.
Which versions of WavPack are affected by CVE-2019-1010317?
WavPack versions 5.1.0 and earlier are affected by CVE-2019-1010317.
What is the nature of the vulnerability CVE-2019-1010317?
CVE-2019-1010317 is caused by the use of uninitialized variables in the ParseCaffHeaderConfig function.
What are the implications of CVE-2019-1010317 for users?
Users may experience crashes or unexpected behavior when processing maliciously crafted .wav files due to CVE-2019-1010317.