ID:3784 - Exploit for Infinite loop in SoundTouch - CVE-2017-9258

 
Main Vulnerability Database Exploits ID:3784 - Exploit for Infinite loop in SoundTouch - CVE-2017-9258

ID:3784 - Exploit for Infinite loop in SoundTouch - CVE-2017-9258

Published: August 9, 2020


Vulnerability identifier: #VU38638
Vulnerability risk: Medium
CVE-ID: CVE-2017-9258
CWE-ID: CWE-835
Exploitation vector: Remote access
Vulnerable software:
SoundTouch

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.


Remediation

Install update from vendor's website.