Hide Forgot
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. Upstream issue: https://gitlab.com/soundtouch/soundtouch/issues/14 References: https://github.com/TeamSeri0us/pocs/tree/master/soundtouch/2018_09_03
Created soundtouch tracking bugs for this issue: Affects: epel-6 [bug 1631066] Affects: fedora-all [bug 1631065]
The root cause of this issue is the same as of CVE-2018-17097. The same upstream patch fixes both issues: https://gitlab.com/soundtouch/soundtouch/commit/7f594f8b7d10bbc16a4a31de8ec5a279af9c7378
Statement: This issue did not affect the versions of soundtouch as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.