#VU19217 Improper Initialization in WavPack - CVE-2019-1010317
Published: July 17, 2019 / Updated: July 17, 2019
WavPack
wavpack
Description
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on a targeted system.
The vulnerability exists due to an uninitialized read condition in the "ParseCaffHeaderConfig()" function in the caff.c file when parsing .wav files. A remote attacker can persuade a user to access a .wav file that submits malicious input to the targeted system and perform a DoS attack.