Candidate: CVE-2018-17098 PublicDate: 2018-09-16 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17098 https://gitlab.com/soundtouch/soundtouch/issues/14 https://github.com/TeamSeri0us/pocs/blob/master/soundtouch/2018_09_03 Description: The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. Ubuntu-Description: It was discovered that SoundTouch incorrectly handled certain WAV files. A remote attacker could possibly use this issue to cause a denial of service or other unspecified impact. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_soundtouch: upstream_soundtouch: needs-triage precise/esm_soundtouch: DNE trusty_soundtouch: ignored (out of standard support) trusty/esm_soundtouch: needed xenial_soundtouch: ignored (end of standard support, was needed) bionic_soundtouch: needed cosmic_soundtouch: ignored (reached end-of-life) disco_soundtouch: released (2.1.2+ds1-1) eoan_soundtouch: released (2.1.2+ds1-1) focal_soundtouch: released (2.1.2+ds1-1) groovy_soundtouch: released (2.1.2+ds1-1) hirsute_soundtouch: released (2.1.2+ds1-1) impish_soundtouch: released (2.1.2+ds1-1) jammy_soundtouch: released (2.1.2+ds1-1) devel_soundtouch: released (2.1.2+ds1-1)