A flaw was found in Olli Parviainen SoundTouch 2.0. The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch. References: https://github.com/TeamSeri0us/pocs/blob/master/soundtouch/readme.md
Created soundtouch tracking bugs for this issue: Affects: epel-6 [bug 1601621] Affects: fedora-all [bug 1601620]
Upstream issue: https://gitlab.com/soundtouch/soundtouch/issues/7
This is fixed by the following upstream commit: https://gitlab.com/soundtouch/soundtouch/commit/107f2c5d201a4dfea1b7f15c5957ff2ac9e5f260