soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack appear to be exploitable via victim must open maliocius file in soundstretch utility.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade soundtouch | Jul 30, 2024 | Aug 20, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade soundtouch | Sep 16, 2021 | Aug 20, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade soundtouch | Apr 30, 2021 | Aug 20, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade soundtouch | Mar 24, 2021 | Aug 20, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 20, 2018 |
| Suse | — | Upgrade soundtouch-develUpgrade libSoundTouch0-32bitUpgrade libSoundTouch0Upgrade soundtouch | Oct 9, 2018 | Aug 20, 2018 |
| Ubuntu | — | Upgrade libsoundtouch1 (Ubuntu Pro)Upgrade libsoundtouch0 (Ubuntu Pro)Upgrade soundstretch (Ubuntu Pro) | Mar 22, 2023 | Aug 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub