Buffer overread in aubio - CVE-2018-14523
Published: August 20, 2018
aubio
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition on the target system.
The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into processing specially crafted data, trigger buffer over-read in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotesa and obtain potentially sensitive information or cause the service to crash.