SB2019013137 - Infinite loop in wavpack (Alpine package)
Published: January 31, 2019
Security Bulletin ID
SB2019013137
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2018-19840)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the WavpackPackInit function, as defined in the pack_utils.csource code file due to the WavpackSetConfiguration64 function improperly handles a block sample rate of zero. A remote attacker can trick the victim into accessing a .wav file that submits malicious, trigger an infinite loop condition that could consume excessive resources and cause the affected software to crash, resulting in a DoS condition.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=fcfac0bb84e91ad39d8554e3ff04d2aacc625915
- https://git.alpinelinux.org/aports/commit/?id=ac2fd8a89cfc84daba107884f80429f966353415
- https://git.alpinelinux.org/aports/commit/?id=7cca64b825df9ba1e75a7b5b58c7f189f42e28d1
- https://git.alpinelinux.org/aports/commit/?id=b5b80b2b87d036148c7314cd653d8cf8f57c9556
- https://git.alpinelinux.org/aports/commit/?id=e58c4039fb96953e79558384100a86f6a56c32f2
- https://git.alpinelinux.org/aports/commit/?id=e5938228bdfcb80390ff361b79966fdcf0fdb35a
- https://git.alpinelinux.org/aports/commit/?id=f06887bf6720ff8c26e5a7e3b87488cb2be83be2