CVE-2019-1010319: Medium severity WavPack Wavpack vulnerability
Last updated 25 August 2025
Other sources
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010319?
CVE-2019-1010319 has a moderate severity due to potential crashes and unexpected control flow.
How do I fix CVE-2019-1010319?
To fix CVE-2019-1010319, update WavPack to version 5.1.0-2ubuntu1.4 or later for Ubuntu and to version 5.4.0-1 or later for Debian.
What is the impact of CVE-2019-1010319?
The impact of CVE-2019-1010319 includes the potential for application crashes and segmentation faults when processing maliciously crafted .wav files.
Which versions of WavPack are affected by CVE-2019-1010319?
Versions of WavPack up to and including 5.1.0 are affected by CVE-2019-1010319.
Can CVE-2019-1010319 be exploited remotely?
Yes, CVE-2019-1010319 can be exploited remotely through the use of maliciously crafted .wav files.