CVE-2018-17098Out-of-bounds Write in Soundtouch

Severity
8.8HIGHNVD
OSV5.5
EPSS
1.3%
top 20.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 13

Description

The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/soundtouch< soundtouch 2.1.2+ds1-1 (bookworm)
Debiansurina/soundtouch< 2.1.2+ds1-1+3
Ubuntusurina/soundtouch< 1.7.1-5ubuntu0.1~esm1+2

🔴Vulnerability Details

3
GHSA
GHSA-3j4v-h6mr-q2j9: The WavFileBase class in WavFile2022-05-13
OSV
soundtouch vulnerabilities2021-03-15
OSV
CVE-2018-17098: The WavFileBase class in WavFile2018-09-16

📋Vendor Advisories

3
Ubuntu
SoundTouch vulnerabilities2021-03-15
Red Hat
soundtouch: Heap corruption in WavFileBase class in WavFile.cpp2018-09-17
Debian
CVE-2018-17098: soundtouch - The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows re...2018

💬Community

4
Bugzilla
CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in WavFile.cpp [fedora-all]2018-09-19
Bugzilla
CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in WavFile.cpp [epel-6]2018-09-19
Bugzilla
CVE-2018-17096 soundtouch: Assertion failure in BPMDetect class in BPMDetect.cpp2018-09-19
Bugzilla
CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in WavFile.cpp2018-09-19