Double-free error in SoundTouch - CVE-2018-17097
Published: November 19, 2018
Vulnerability identifier: #VU15947
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17097
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to double-free error in WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch. A remote attacker can send specially crafted input and cause the application exit, as demonstrated by SoundStretch.
Affected software
SoundTouch
soundtouch (Alpine package)
soundtouch
Opensuse
Fedora
soundtouch (Alpine package)
soundtouch
Opensuse
Fedora
How to mitigate CVE-2018-17097
Update to version 2.1.
SoundTouch - update to 2.1
soundtouch (Alpine package) - update to 2.1.2-r0
soundtouch - addressed in versions 2.1.1-1.fc27, 2.1.1-1.fc28, 2.1.1-1.fc29
soundtouch (Alpine package) - update to 2.1.2-r0
soundtouch - addressed in versions 2.1.1-1.fc27, 2.1.1-1.fc28, 2.1.1-1.fc29