CVE-2019-11498: Medium severity wavpack vulnerability
WavpackSetConfiguration64 in packutils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11498?
CVE-2019-11498 has a severity rating that indicates it can cause a denial of service due to an application crash.
How do I fix CVE-2019-11498?
To fix CVE-2019-11498, update WavPack to version 5.1.0-2ubuntu1.3 or later for Ubuntu or to version 5.4.0-1 or later for Debian.
Which software versions are affected by CVE-2019-11498?
CVE-2019-11498 affects WavPack versions up to 5.1.0, including specific versions in Ubuntu and Debian distributions.
Can CVE-2019-11498 be exploited remotely?
CVE-2019-11498 could potentially be exploited by an attacker through a specially crafted DFF file.
What should I do if I am using WavPack and impacted by CVE-2019-11498?
If you are using an affected version of WavPack, you should immediately update to the fixed versions to prevent possible denial of service.