Red Hat Bugzilla – Bug 1475756
CVE-2017-9260 soundtouch: Heap-buffer over-read in the TDStretchSSE::calcCrossCorr function
Last modified: 2017-07-27 05:34:34 EDT
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file. References: http://seclists.org/fulldisclosure/2017/Jul/62
Created soundtouch tracking bugs for this issue: Affects: epel-6 [bug 1475760] Affects: fedora-all [bug 1475759]