CVE-2018-17098 — Out-of-bounds Write in Soundtouch
Severity
8.8HIGHNVD
OSV5.5
EPSS
1.3%
top 20.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 13
Description
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
4Bugzilla▶
CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in WavFile.cpp [fedora-all]↗2018-09-19
Bugzilla
▶
Bugzilla
▶