Bug 1631064 (CVE-2018-17098) - CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in WavFile.cpp
Summary: CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in WavFile.cpp
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-17098
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1631065 1631066 1631067
Blocks: 1631058
TreeView+ depends on / blocked
 
Reported: 2018-09-19 20:11 UTC by Pedro Sampaio
Modified: 2021-10-25 22:18 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-25 22:18:03 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2018-09-19 20:11:32 UTC
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.

Upstream issue:

https://gitlab.com/soundtouch/soundtouch/issues/14

References:

https://github.com/TeamSeri0us/pocs/tree/master/soundtouch/2018_09_03

Comment 1 Pedro Sampaio 2018-09-19 20:12:04 UTC
Created soundtouch tracking bugs for this issue:

Affects: epel-6 [bug 1631066]
Affects: fedora-all [bug 1631065]

Comment 3 Adam Mariš 2018-11-07 14:09:34 UTC
The root cause of this issue is the same as of CVE-2018-17097. The same upstream patch fixes both issues:

https://gitlab.com/soundtouch/soundtouch/commit/7f594f8b7d10bbc16a4a31de8ec5a279af9c7378

Comment 4 Adam Mariš 2018-11-07 14:10:53 UTC
Statement:

This issue did not affect the versions of soundtouch as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.


Note You need to log in before you can comment on or make changes to this bug.