Mageia 2019-0231: wavpack security update
Summary
Updated wavpack packages fixes security vulnerabilities:
Rohan Padhye discovered that WavPack incorrectly handled certain WAV files.
An attacker could possibly use this issue to cause a denial of service
(CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319).
References
- https://bugs.mageia.org/show_bug.cgi?id=25265
- https://ubuntu.com/security/notices/USN-4062-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010315
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010317
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010318
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010319
Resolution
MGASA-2019-0231 - Updated wavpack packages fix security vulnerabilities
SRPMS
- 7/core/wavpack-5.1.0-4.1.mga7