SB2019082328 - Improper Initialization in wavpack (Alpine package)
Published: August 23, 2019
Security Bulletin ID
SB2019082328
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Initialization (CVE-ID: CVE-2019-1010319)
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the targeted system.
The vulnerability exists due to an uninitialized read condition in the "ParseWave64HeaderConfig()" function in "wave64.c" file when parsing .wav files. A remote attacker can trick a victim to open a specially crafted .wav file and crash the affected application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=fcfac0bb84e91ad39d8554e3ff04d2aacc625915
- https://git.alpinelinux.org/aports/commit/?id=191092674935c795b8225c2830c1511c58e07b13
- https://git.alpinelinux.org/aports/commit/?id=a72e9dec2ca905acb1090eae42c239c177a553f0
- https://git.alpinelinux.org/aports/commit/?id=ac2fd8a89cfc84daba107884f80429f966353415
- https://git.alpinelinux.org/aports/commit/?id=cf8d2a4da0a509445e4b9e7eda5074c70fad88c6
- https://git.alpinelinux.org/aports/commit/?id=d30d51c92e7333a663a22b2775a0b3f2dcadf976