openSUSE-SU-2019:2067-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2067-1
openSUSE-SU-2019:2067-1
Summary: Security update for wavpack
Details: This update for wavpack fixes the following issues: Security issues fixed: - CVE-2019-1010319: Fixed use of uninitialized variable in ParseWave64HeaderConfig that can result in unexpected control flow, crashes, and segfaults (bsc#1141334). - CVE-2019-11498: Fixed possible denial of service (application crash) in WavpackSetConfiguration64 via a DFF file that lacks valid sample-rate data (bsc#1133384). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/KDMSNPSLTLO63QUMM222SJH6HOTD67XF/#KDMSNPSLTLO63QUMM222SJH6HOTD67XF, https://bugzilla.suse.com/1133384, https://bugzilla.suse.com/1141334, https://www.suse.com/security/cve/CVE-2019-1010319, https://www.suse.com/security/cve/CVE-2019-11498
Affected packages
Package
Name: wavpack
Purl: pkg:rpm/opensuse/wavpack&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
