Updated wavpack packages fixes security vulnerabilities:
It was discovered that WavPack incorrectly handled certain DFF files.
An attacker could possibly use this issue to cause a denial of service
(CVE-2019-11498).
Rohan Padhye discovered that WavPack incorrectly handled certain WAV files.
An attacker could possibly use this issue to cause a denial of service
(CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319).
- https://bugs.mageia.org/show_bug.cgi?id=25265
- https://ubuntu.com/security/notices/USN-3960-1
- https://ubuntu.com/security/notices/USN-4062-1
- https://www.cve.org/CVERecord?id=CVE-2019-11498
- https://www.cve.org/CVERecord?id=CVE-2019-1010315
- https://www.cve.org/CVERecord?id=CVE-2019-1010317
- https://www.cve.org/CVERecord?id=CVE-2019-1010318
- https://www.cve.org/CVERecord?id=CVE-2019-1010319
- 6/core/wavpack-5.1.0-1.2.mga6
Get the latest Linux and open source security news straight to your inbox.