#VU19216 Division by zero in WavPack - CVE-2019-1010315
Published: July 17, 2019 / Updated: July 24, 2019
WavPack
wavpack
Description
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on a targeted system.
The vulnerability exists due to a divide by zero error in the "ParseDsdiffHeaderConfig()" function in the "dsdiff.c" file, when parsing .wav files.
A remote attacker can trick a victim to open a specially crafted .wav file and crash the affected application.