CVE-2018-17096Reachable Assertion in Soundtouch

Severity
6.5MEDIUMNVD
OSV5.5
EPSS
0.3%
top 49.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 13

Description

The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/soundtouch< soundtouch 2.1.2+ds1-1 (bookworm)
Debiansurina/soundtouch< 2.1.2+ds1-1+3
Ubuntusurina/soundtouch< 1.7.1-5ubuntu0.1~esm1+2

🔴Vulnerability Details

3
GHSA
GHSA-h6fq-f4xm-h8jq: The BPMDetect class in BPMDetect2022-05-13
OSV
soundtouch vulnerabilities2021-03-15
OSV
CVE-2018-17096: The BPMDetect class in BPMDetect2018-09-16

📋Vendor Advisories

3
Ubuntu
SoundTouch vulnerabilities2021-03-15
Red Hat
soundtouch: Assertion failure in BPMDetect class in BPMDetect.cpp2018-09-17
Debian
CVE-2018-17096: soundtouch - The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen Sound...2018

💬Community

3
Bugzilla
CVE-2018-17096 soundtouch: Assertion failure in BPMDetect class in BPMDetect.cpp2018-09-19
Bugzilla
CVE-2018-17096 soundtouch: Assertion failure in BPMDetect class in BPMDetect.cpp [epel-6]2018-09-19
Bugzilla
CVE-2018-17096 soundtouch: Assertion failure in BPMDetect class in BPMDetect.cpp [fedora-all]2018-09-19