PT-2017-18809 · Olli Parviainen+2 · Soundtouch+2

Qflb.Wu

·

Publicado

2017-07-27

·

Atualizado

2021-03-15

·

CVE-2017-9258

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SoundTouch version 1.9.2
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and CPU consumption, via a crafted wav file. This is due to a problem in the TDStretch::processSamples function in the source/SoundTouch/TDStretch.cpp file.
Recommendations For version 1.9.2, consider disabling the TDStretch::processSamples function as a temporary workaround until a patch is available. Restrict access to processing crafted wav files to minimize the risk of exploitation.

Exploit

Correção

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1964
CVE-2017-9258
MGASA-2018-0331
MGASA-2020-0193
USN-4826-1

Produtos afetados

Alt Linux
Soundtouch
Ubuntu