Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2020-0317 Severe: WavPack Buffer Overflow Vulnerabilities

mageia
Calendar Grey August 31, 2019
Dist Mageia Esm H88
Mageia has patched the lz4 packages to resolve critical security vulnerabilities identified by Rohan Padhye.
Updated wavpack packages fixes security vulnerabilities: Rohan Padhye discovered that WavPack incorrectly handled certain WAV files

Summary

Updated wavpack packages fixes security vulnerabilities:
Rohan Padhye discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319).

References

- https://bugs.mageia.org/show_bug.cgi?id=25265

- https://ubuntu.com/security/notices/USN-4062-1

- https://www.cve.org/CVERecord?id=CVE-2019-1010315

- https://www.cve.org/CVERecord?id=CVE-2019-1010317

- https://www.cve.org/CVERecord?id=CVE-2019-1010318

- https://www.cve.org/CVERecord?id=CVE-2019-1010319

Resolution

SRPMS

- 7/core/wavpack-5.1.0-4.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 31 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0231.html
Type: security
CVE: CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here