==========================================================================
Ubuntu Security Notice USN-3960-1
April 30, 2019
wavpack vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 19.04
– Ubuntu 18.10
– Ubuntu 18.04 LTS
Summary:
WavPack could be made to crash if it received a specially
crafted file.
Software Description:
– wavpack: audio codec (lossy and lossless) – encoder and decoder
Details:
It was discovered that WavPack incorrectly handled certain DFF files.
An attacker could possibly use this issue to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.04:
libwavpack1 5.1.0-5ubuntu0.1
wavpack 5.1.0-5ubuntu0.1
Ubuntu 18.10:
libwavpack1 5.1.0-4ubuntu0.2
wavpack 5.1.0-4ubuntu0.2
Ubuntu 18.04 LTS:
libwavpack1 5.1.0-2ubuntu1.3
wavpack 5.1.0-2ubuntu1.3
In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3960-1
CVE-2019-11498
Package Information:
https://launchpad.net/ubuntu/+source/wavpack/5.1.0-5ubuntu0.1
https://launchpad.net/ubuntu/+source/wavpack/5.1.0-4ubuntu0.2
https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu1.3—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2
iQIcBAABCAAGBQJcyFsfAAoJEEW851uECx9p+LoP/3CgmQdLD5BCjT6OlCDhnPNG
nCE5W0Zo2YBa0sldxwWfEFRQQSRPVUic5DgcYlYyIgZXvejhMdtl5cA98sD+nLr0
qTwTZJn5pj4c/EkXifh6QVzCLMIwj8Oe9//BKsIu86hXYcihFgko7Z7vM45xSJuv
XbSpnM4wFVKMkFtpeBk04S+fc+bAb+kr3h5EqL5MwpoyU7hESuQOBt6LgfDQbKDP
D/awR/TmDnBHUdPtLj/viffQy9hSpuczPt+iYrlso95rkDZ6Zc3LG4pYrnIg7p+B
KS5xquR4kdV8WiQzMHzA8LCZo2A7XOMLSeyF/1EDtshd7Nc6tnB3L6gBUOSVG7YG
XWUup13eQcanmXPRGUVWGbspU1j17/pfZYfHfSPirNi+7zWjnjhWDpA30wwn4EqJ
YoMC+X33xtnNgCH7QNKaRv3jp0dFG9TRgmlV1FwfBH/ClYBcQA9IoSr6ozjdVa7e
bUZhFR3E9yfp1rSafcBUvjjVON3cHA9vifEFKtUs7honphjW4HXNgw7d0NDoA61R
jeF3LKmsHoiptQ7RIgcAmEhOQrcLu718vQTT4M7Kjym+Is9lj1bq7mdzBAg2R3jF
tZoIDfezq9mLDRz8OxFjoqg/hoXptr0KmziYbp56m5Ln96jSvbjjfS3m+ov9fon5
Rx9A1NYzTqwd6y9LoWl7
=tbeh
—–END PGP SIGNATURE—–
—