PT-2018-12564 · Aubio+1 · Aubio+1

Fcorleone

·

Published

2018-07-23

·

Updated

2022-05-13

·

CVE-2018-14523

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aubio version 0.4.6
Description An issue was discovered in aubio where a buffer over-read can occur in the new aubio pitchyinfft function in pitch/pitchyinfft.c. This issue is demonstrated by aubionotes and can occur when the samplerate of the input file is larger than 50kHz.
Recommendations For aubio version 0.4.6, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14523
GHSA-3X58-8QMV-WQW5
MGASA-2019-0016
OPENSUSE-SU-2018:2810-1
OPENSUSE-SU-2018_2343-1
OPENSUSE-SU-2019:1049-1
OPENSUSE-SU-2019:1229-1
PYSEC-2018-63

Affected Products

Suse
Aubio