Hide Forgot
WavInFile::readHeaderBlock() function in SoundStretch/WavFile.cpp is vulnerable to heap buffer overflow that can lead to arbitrary code execution when processing malicious file. This issue does affect only SoundStretch utility, not SoundTouch library. Upstream issue: https://gitlab.com/soundtouch/soundtouch/issues/6
Created soundtouch tracking bugs for this issue: Affects: epel-6 [bug 1609195] Affects: fedora-all [bug 1609194]
Upstream fix: https://gitlab.com/soundtouch/soundtouch/commit/9e02d9b04fda6c1f44336ff00bb5af1e2ffc039e https://gitlab.com/soundtouch/soundtouch/commit/e0240689056e4182fffdc2a16aa6e3425a15e275 https://gitlab.com/soundtouch/soundtouch/commit/46531e5b92dd80dd9a7947463d6224fc7cb21967