SB2019082327 - Improper Initialization in wavpack (Alpine package)
Published: August 23, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Initialization (CVE-ID: CVE-2019-1010317)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on a targeted system.
The vulnerability exists due to an uninitialized read condition in the "ParseCaffHeaderConfig()" function in the caff.c file when parsing .wav files. A remote attacker can persuade a user to access a .wav file that submits malicious input to the targeted system and perform a DoS attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=fcfac0bb84e91ad39d8554e3ff04d2aacc625915
- https://git.alpinelinux.org/aports/commit/?id=191092674935c795b8225c2830c1511c58e07b13
- https://git.alpinelinux.org/aports/commit/?id=a72e9dec2ca905acb1090eae42c239c177a553f0
- https://git.alpinelinux.org/aports/commit/?id=ac2fd8a89cfc84daba107884f80429f966353415
- https://git.alpinelinux.org/aports/commit/?id=cf8d2a4da0a509445e4b9e7eda5074c70fad88c6
- https://git.alpinelinux.org/aports/commit/?id=d30d51c92e7333a663a22b2775a0b3f2dcadf976