WavPack: Multiple vulnerabilities Multiple vulnerabilities have been found in WavPack, the worst of which could result in a Denial of Service condition. wavpack 2020-07-27 2020-07-27 672638 remote 5.3.2 5.3.2

WavPack is a set of hybrid lossless audio compression tools.

Multiple vulnerabilities have been discovered in WavPack. Please review the CVE identifiers referenced below for details.

A remote attacker could send a specially crafted audio file possibly resulting in a Denial of Service condition. Please review the referenced CVE identifiers for details.

There is no known workaround at this time.

All WavPack users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-sound/wavpack-5.3.2"
CVE-2018-19840 CVE-2018-19841 CVE-2019-11498 sam_c sam_c