SB2019082329 - Input validation error in wavpack (Alpine package)
Published: August 23, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-11498)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the WavpackSetConfiguration64() function in the pack_utils.c file within the libwavpack.a. A remote attacker can trick the victim to open a specially crafted DFF file that lacks valid sample-rate data and crash the affected application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=fcfac0bb84e91ad39d8554e3ff04d2aacc625915
- https://git.alpinelinux.org/aports/commit/?id=191092674935c795b8225c2830c1511c58e07b13
- https://git.alpinelinux.org/aports/commit/?id=a72e9dec2ca905acb1090eae42c239c177a553f0
- https://git.alpinelinux.org/aports/commit/?id=ac2fd8a89cfc84daba107884f80429f966353415
- https://git.alpinelinux.org/aports/commit/?id=cf8d2a4da0a509445e4b9e7eda5074c70fad88c6
- https://git.alpinelinux.org/aports/commit/?id=d30d51c92e7333a663a22b2775a0b3f2dcadf976