Assertion failure in SoundTouch - CVE-2018-17096
Published: November 12, 2018 / Updated: November 19, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to assertion failure in BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch. A remote attacker can send specially crafted input and cause the application exit, as demonstrated by SoundStretch.
Affected software
soundtouch (Alpine package)
soundtouch
Opensuse
Fedora
How to mitigate CVE-2018-17096
soundtouch (Alpine package) - update to 2.1.2-r0
soundtouch - addressed in versions 2.1.1-1.fc27, 2.1.1-1.fc28, 2.1.1-1.fc29