WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe.
[ { "signature_type": "Line", "deprecated": false, "source": "https://github.com/dbry/wavpack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe", "signature_version": "v1", "target": { "file": "cli/wave64.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "122404160467285183712511770525712175680", "285219514396165490106202596329857256961", "329377426616782729961540193952241123862" ] }, "id": "CVE-2019-1010319-38995bcb" }, { "signature_type": "Function", "deprecated": false, "source": "https://github.com/dbry/wavpack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe", "signature_version": "v1", "target": { "function": "ParseWave64HeaderConfig", "file": "cli/wave64.c" }, "digest": { "function_hash": "164572977520454645612894174087013665163", "length": 6740.0 }, "id": "CVE-2019-1010319-9c2e723c" } ]