GHSA-3x58-8qmv-wqw5
Dashboard / Vulnerabilities / GHSA-3x58-8qmv-wqw5
GHSA-3x58-8qmv-wqw5
Summary: Aubio is vulnerable to out of bound read when samplerate > 50kHz
Details: An issue was discovered in aubio 0.4.6. A buffer over-read can occur in `new_aubio_pitchyinfft` in `pitch/pitchyinfft.c` when the samplerate of the input file is larger than 50kHz.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-14523, https://github.com/aubio/aubio/issues/189, https://github.com/aubio/aubio/commit/af4f9e6a93b629fb6defa2a229ec828885b9d187, https://github.com/aubio/aubio, https://github.com/pypa/advisory-database/tree/main/vulns/aubio/PYSEC-2018-63.yaml, http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00031.html, http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00071.html
Affected packages
Package
Name: aubio
Purl: pkg:pypi/aubio
Affected ranges
Type: ECOSYSTEM
Events:
