Debian 9924 Published by

A wavpack security update has been released for Debian GNU/Linux 8 Extended LTS to address multiple vulnerabilities like OOB read (which could potentially lead to a DOS attack), unexpected control flow, crashes, integer overflow, and segfaults.



ELA-346-1 wavpack security update

Package wavpack
Version 4.70.0-1+deb8u1
Related CVEs CVE-2016-10169 CVE-2018-19840 CVE-2019-1010319 CVE-2020-35738
Multiple vulnerabilites in wavpack were found, like OOB read (which could potentially lead to a DOS attack), unexpected control flow, crashes, integer overflow, and segfaults.

For Debian 8 jessie, these problems have been fixed in version 4.70.0-1+deb8u1.

We recommend that you upgrade your wavpack packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-346-1 wavpack security update