Red Hat Bugzilla – Bug 1601624
CVE-2018-14045 soundtouch: Reachable assertion in FIRFilter.cpp causing denial of service
Last modified: 2018-08-14 10:28:06 EDT
A flaw was found in Olli Parviainen SoundTouch 2.0. The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch. References: https://github.com/TeamSeri0us/pocs/blob/master/soundtouch/readme.md
Created soundtouch tracking bugs for this issue: Affects: epel-6 [bug 1601626] Affects: fedora-all [bug 1601625]
Upstream issue: https://gitlab.com/soundtouch/soundtouch/issues/7
Statement: This issue did not affect the versions of soundtouch as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.
This is fixed by the following upstream commit: https://gitlab.com/soundtouch/soundtouch/commit/107f2c5d201a4dfea1b7f15c5957ff2ac9e5f260