MGASA-2019-0230

Source
https://advisories.mageia.org/MGASA-2019-0230.html
Import Source
https://advisories.mageia.org/MGASA-2019-0230.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0230
Related
Published
2019-08-31T13:22:36Z
Modified
2019-08-31T12:31:15Z
Summary
Updated wavpack packages fix security vulnerabilities
Details

Updated wavpack packages fixes security vulnerabilities:

It was discovered that WavPack incorrectly handled certain DFF files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-11498).

Rohan Padhye discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319).

References
Credits

Affected packages

Mageia:6 / wavpack

Package

Name
wavpack
Purl
pkg:rpm/mageia/wavpack?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.0-1.2.mga6

Ecosystem specific

{
    "section": "core"
}