Lucene search

K
cvelistDwfCVELIST:CVE-2019-1010319
HistoryJul 11, 2019 - 7:23 p.m.

CVE-2019-1010319

2019-07-1119:23:29
CWE-457
dwf
www.cve.org
6

AI Score

6

Confidence

High

EPSS

0.002

Percentile

58.6%

WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe.

CNA Affected

[
  {
    "product": "WavPack",
    "vendor": "WavPack",
    "versions": [
      {
        "status": "affected",
        "version": "<=5.1.0 [fixed: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe]"
      }
    ]
  }
]