Back

MEDIUM

wawpack: Infinite loop in WavpackPackInit function lead to DoS

Published Dec 4, 2018

Description

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

Affected products

Remediation

Red Hat statement

This issue affects the versions of wavpack as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Weaknesses (1)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 4, 2018
Updated Aug 5, 2024
Reserved Dec 3, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 26, 2018
ENISA EUVD
Assigner mitre
Published Dec 4, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-11515