GHSA-7vvr-h4p5-m7fh
Dashboard / Vulnerabilities / GHSA-7vvr-h4p5-m7fh
GHSA-7vvr-h4p5-m7fh
Summary: Aubio is vulnerable to a NULL pointer dereference in new_aubio_filterbank
Details: aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in `new_aubio_filterbank` via invalid n_filters.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-19801, https://github.com/advisories/GHSA-7vvr-h4p5-m7fh, https://github.com/aubio/aubio, https://github.com/aubio/aubio/blob/0.4.9/ChangeLog, https://github.com/pypa/advisory-database/tree/main/vulns/aubio/PYSEC-2019-163.yaml, https://lists.fedoraproject.org/archives/list/[email protected]/message/IYIKPYXZIWYWWNNORSKWRCFFCP6AFMRZ, https://lists.fedoraproject.org/archives/list/[email protected]/message/OHIRMWW4JQ6UHJK4AVBJLFRLE2TPKC2W, http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00063.html, http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00067.html
Affected packages
Package
Name: aubio
Purl: pkg:pypi/aubio
Affected ranges
Type: ECOSYSTEM
Events:
