Heap-based buffer overflow in SoundTouch - CVE-2018-17098
Published: November 19, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to heap-based buffer overflow in WavFileBase class in WavFile.cpp in in Olli Parviainen SoundTouch. A remote attacker can send specially crafted input, trigger memory corruption and cause the application exit, as demonstrated by SoundStretch.
Affected software
soundtouch (Alpine package)
soundtouch
Opensuse
Fedora
How to mitigate CVE-2018-17098
soundtouch (Alpine package) - update to 2.1.2-r0
soundtouch - addressed in versions 2.1.1-1.fc27, 2.1.1-1.fc28, 2.1.1-1.fc29