libwavpack-dev - audio codec (lossy and lossless) - development files

Distribution Ubuntu 18.04 LTS (Bionic Beaver)
Repository Ubuntu Updates Main i386
Package filename libwavpack-dev_5.1.0-2ubuntu1.4_i386.deb
Package name libwavpack-dev
Package version 5.1.0
Package release 2ubuntu1.4
Package architecture i386
Package type deb
Category libdevel
License -
Maintainer Ubuntu Developers <>
Download size 93.05 KB
Installed size 286.00 KB
WavPack is a completely open audio compression format providing lossless,
high-quality lossy, and a unique hybrid compression mode. Although the
technology is loosely based on previous versions of WavPack, the new version
4 format has been designed from the ground up to offer unparalleled
performance and functionality.
This package contains the header files, static libraries
and symbolic links that developers using libwavpack will need.


2019-07-16 - Leonidas S. Barbosa <>
wavpack (5.1.0-2ubuntu1.4) bionic-security; urgency=medium
* debian/0009-issue-41-make-sure-DFF-does-not*.patch: make sure
DFF chunk does not have negative length.
* debian/patches/0010-issue-43-catch-zero*.patch: catch zero
channel count in DSF and DSDIFF files.
* SECURITY UPDATE: Crash due a divide by zero
- debian/patches/CVE-2019-1010315.patch: make sure DSDIFF files
have a valid channel count in cli/dsdiff.c.
- CVE-2019-1010315
* SECURITY UPDATE: Crashes and segfaults
- debian/patches/CVE-2019-1010317.patch: make sure CAF files
have a "desc" chunk in cli/caff.c.
- CVE-2019-1010317
* SECURITY UPDATE: Crashes and segfaults
- debian/patches/CVE-2019-1010318.patch: make sure sample rate is
specified and non-zero in DFF files in cli/dsdiff.c.
- CVE-2019-1010318
* SECURITY UPDATE: Crashes and segfaults
- debian/patches/CVE-2019-1010319.patch: clear WaveHeader at start
to prevent uninitialized read in cli/wave64.c.
- CVE-2019-1010319
2019-04-29 - Leonidas S. Barbosa <>
wavpack (5.1.0-2ubuntu1.3) bionic-security; urgency=medium
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2019-11498.patch: make sure sample rate variable
is specified and non-zero in DFF files in cli/dsdiff.c.
- CVE-2019-11498
2018-12-06 - Leonidas S. Barbosa <>
wavpack (5.1.0-2ubuntu1.2) bionic-security; urgency=medium
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-19840.patch: checking
if sample_rate is not zero in src/pack_utils.c.
- CVE-2018-19840
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-19841.patch: fix in
2018-04-30 - Leonidas S. Barbosa <>
wavpack (5.1.0-2ubuntu1.1) bionic-security; urgency=medium
* SECURITY UPDATE: Writing to memory vulnerability in wav64 and riff
- debian/patches/CVE-2018-10536-and-10537.patch: fixing in cli/riff.c,
- CVE-2018-10536
- CVE-2018-10537
* SECURITY UPDATE: Out-of-bounds writes in riff, DSDiff and W64
- debian/patches/CVE-2018-10538-and-10539-and-10540.patch: sanitize
size of unknown chunks before malloc in cli/dsdiff.c, cli/riff.c,
- CVE-2018-10538
- CVE-2018-10539
- CVE-2018-10540
2018-02-22 - Leonidas S. Barbosa <>
wavpack (5.1.0-2ubuntu1) bionic; urgency=medium
* SECURITY UPDATE: stack-based buffer overr-read
- debian/patches/CVE-2018-6767.patch: do not overwrite
stack on corrupt RF64 file in cli/riff.c.
- CVE-2018-6767
* SECURITY UPDATE: Maliciously crafted DSDIFF can result
in a denial of service
- debian/patches/CVE-2018-7253.patch: do not overwrite
heap on corrupt DSDIFF file in cli/dsdiff.c
- CVE-2018-7253
* SECURITY UPDATE: Denial of service through maliciously
crafted CAF file
- debian/patches/CVE-2018-7254.patch: fix buffer overflows
and bad allocs in cli/caff.c.
- CVE-2018-7254
2017-07-09 - Loïc Minier <>
wavpack (5.1.0-2) unstable; urgency=medium
* Bump Standards-Version to 4.0.0.
* Drop myself from Uploaders.
2017-06-15 - Sebastian Ramacher <>
wavpack (5.1.0-1) unstable; urgency=medium
* Team upload.
* New upstream release.
* debian/patches: Removed patches included upstream.
* debian/copyright: Update copyright years.
2017-01-30 - Sebastian Ramacher <>
wavpack (5.0.0-2) unstable; urgency=medium
* Team upload.
* debian/patches: Apply upstream fix to fix some fuzz failures
(CVE-2016-10169, CVE-2016-10170, CVE-2016-10171, CVE-2016-10172). (Closes:
2017-01-02 - Sebastian Ramacher <>
wavpack (5.0.0-1) unstable; urgency=medium
* Team upload.
* New upstream release.
* debian/libwavpack1.symbols: Add new symbols.
* debian/copyright: Update copyright information.
* debian/control: Bump Standards-Version.

