USN-3960-1: WavPack vulnerability
Published Apr 30, 2019
·Updated
It was discovered that WavPack incorrectly handled certain DFF files. An attacker could possibly use this issue to cause a denial of service.
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/libwavpack1<5.1.0-5ubuntu0.1
5.1.0-5ubuntu0.1
Ubuntu Ubuntu=19.04
All of the following
ubuntu/wavpack<5.1.0-5ubuntu0.1
5.1.0-5ubuntu0.1
Ubuntu Ubuntu=19.04
All of the following
ubuntu/libwavpack1<5.1.0-4ubuntu0.2
5.1.0-4ubuntu0.2
Ubuntu Ubuntu=18.10
All of the following
ubuntu/wavpack<5.1.0-4ubuntu0.2
5.1.0-4ubuntu0.2
Ubuntu Ubuntu=18.10
All of the following
ubuntu/libwavpack1<5.1.0-2ubuntu1.3
5.1.0-2ubuntu1.3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/wavpack<5.1.0-2ubuntu1.3
5.1.0-2ubuntu1.3
Ubuntu Ubuntu=18.04
Event History
Apr 30, 2019
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-3960-1?
USN-3960-1 is categorized as a denial-of-service vulnerability which can be exploited to disrupt service.
2
How do I fix USN-3960-1?
To fix USN-3960-1, update to the latest version of the affected packages for your Ubuntu version.
3
Which versions of Ubuntu are affected by USN-3960-1?
USN-3960-1 affects Ubuntu versions 18.04, 18.10, and 19.04 with specific versions of the libwavpack1 and wavpack packages.
4
What is the main impact of USN-3960-1?
The main impact of USN-3960-1 is a potential denial of service caused by improper handling of DFF files.
5
Who can be affected by USN-3960-1?
Any user or application utilizing the vulnerable versions of WavPack on Ubuntu systems may be impacted by USN-3960-1.