PT-2019-9923 · Aubio+2 · Aubio+2

Guoxiang Niu

+1

·

Published

2019-03-10

·

Updated

2019-07-26

·

CVE-2018-19801

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions aubio versions 0.4.0 through 0.4.8
Description The issue is related to a NULL pointer dereference in the new aubio filterbank function, which occurs when an invalid number of filters (n filters) is provided.
Recommendations For versions 0.4.0 through 0.4.8, as a temporary workaround, consider restricting the use of the new aubio filterbank function with invalid n filters values until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1387
CVE-2018-19801
GHSA-7VVR-H4P5-M7FH
OPENSUSE-SU-2019:1618-1
OPENSUSE-SU-2019:1624-1
OPENSUSE-SU-2019_1618-1
PYSEC-2019-163

Affected Products

Alt Linux
Suse
Aubio