The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade soundtouch | Nov 8, 2019 | Sep 16, 2018 |
| Debian | — | Upgrade soundtouch | Jul 30, 2024 | Sep 16, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 16, 2018 |
| Suse | — | Upgrade soundtouchUpgrade libSoundTouch0 | Nov 3, 2018 | Sep 16, 2018 |
| Ubuntu | — | Upgrade soundstretch (Ubuntu Pro)Upgrade libsoundtouch1 (Ubuntu Pro)Upgrade libsoundtouch0 (Ubuntu Pro) | Mar 22, 2023 | Sep 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub