WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe.
[
{
"digest": {
"line_hashes": [
"122404160467285183712511770525712175680",
"285219514396165490106202596329857256961",
"329377426616782729961540193952241123862"
],
"threshold": 0.9
},
"target": {
"file": "cli/wave64.c"
},
"signature_type": "Line",
"id": "CVE-2019-1010319-38995bcb",
"signature_version": "v1",
"source": "https://github.com/dbry/wavpack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe",
"deprecated": false
},
{
"digest": {
"length": 6740.0,
"function_hash": "164572977520454645612894174087013665163"
},
"target": {
"file": "cli/wave64.c",
"function": "ParseWave64HeaderConfig"
},
"signature_type": "Function",
"id": "CVE-2019-1010319-9c2e723c",
"signature_version": "v1",
"source": "https://github.com/dbry/wavpack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe",
"deprecated": false
}
]