First published: Tue Apr 30 2019(Updated: )
It was discovered that WavPack incorrectly handled certain DFF files. An attacker could possibly use this issue to cause a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libwavpack1 | <5.1.0-5ubuntu0.1 | 5.1.0-5ubuntu0.1 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/wavpack | <5.1.0-5ubuntu0.1 | 5.1.0-5ubuntu0.1 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/libwavpack1 | <5.1.0-4ubuntu0.2 | 5.1.0-4ubuntu0.2 |
Ubuntu OpenSSH Client | =18.10 | |
All of | ||
ubuntu/wavpack | <5.1.0-4ubuntu0.2 | 5.1.0-4ubuntu0.2 |
Ubuntu OpenSSH Client | =18.10 | |
All of | ||
ubuntu/libwavpack1 | <5.1.0-2ubuntu1.3 | 5.1.0-2ubuntu1.3 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/wavpack | <5.1.0-2ubuntu1.3 | 5.1.0-2ubuntu1.3 |
Ubuntu OpenSSH Client | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-3960-1 is categorized as a denial-of-service vulnerability which can be exploited to disrupt service.
To fix USN-3960-1, update to the latest version of the affected packages for your Ubuntu version.
USN-3960-1 affects Ubuntu versions 18.04, 18.10, and 19.04 with specific versions of the libwavpack1 and wavpack packages.
The main impact of USN-3960-1 is a potential denial of service caused by improper handling of DFF files.
Any user or application utilizing the vulnerable versions of WavPack on Ubuntu systems may be impacted by USN-3960-1.