Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Ubuntu 18.04 LTS: USN-3960-1 Moderate: WavPack Denial Of Service

Ubuntu Large Esm H500
WavPack could be made to crash if it received a speciallycrafted file.
=========================================================================Ubuntu Security Notice USN-3960-1
April 30, 2019

wavpack vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS

Summary:

WavPack could be made to crash if it received a specially
crafted file.

Software Description:
- wavpack: audio codec (lossy and lossless) - encoder and decoder

Details:

It was discovered that WavPack incorrectly handled certain DFF files.
An attacker could possibly use this issue to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
  libwavpack1                     5.1.0-5ubuntu0.1
  wavpack                         5.1.0-5ubuntu0.1

Ubuntu 18.10:
  libwavpack1                     5.1.0-4ubuntu0.2
  wavpack                         5.1.0-4ubuntu0.2

Ubuntu 18.04 LTS:
  libwavpack1                     5.1.0-2ubuntu1.3
  wavpack                         5.1.0-2ubuntu1.3

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3960-1
  CVE-2019-11498

Package Information:
  https://launchpad.net/ubuntu/+source/wavpack/5.1.0-5ubuntu0.1
  https://launchpad.net/ubuntu/+source/wavpack/5.1.0-4ubuntu0.2
  https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu1.3

Ubuntu 18.04 LTS: USN-3960-1 Moderate: WavPack Denial Of Service

ubuntu
Calendar Grey April 30, 2019
Dist Ubuntu Esm H88
Addressing WavPack's denial of service risk. Update to mitigate vulnerabilities on Ubuntu installations.
WavPack could be made to crash if it received a speciallycrafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04:   libwavpack1                     5.1.0-5ubuntu0.1   wavpack                         5.1.0-5ubuntu0.1 Ubuntu 18.10:   libwavpack1                     5.1.0-4ubuntu0.2   wavpack                         5.1.0-4ubuntu0.2 Ubuntu 18.04 LTS:   libwavpack1                     5.1.0-2ubuntu1.3   wavpack                         5.1.0-2ubuntu1.3 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3960-1

  CVE-2019-11498

April 30, 2019

Package Information

  https://launchpad.net/ubuntu/+source/wavpack/5.1.0-5ubuntu0.1   https://launchpad.net/ubuntu/+source/wavpack/5.1.0-4ubuntu0.2   https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu1.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here