GHSA-c6jq-h4jp-72pr
Dashboard / Vulnerabilities / GHSA-c6jq-h4jp-72pr
GHSA-c6jq-h4jp-72pr
Summary: Aubio is vulnerable to a NULL pointer dereference in new_aubio_notes function
Details: aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference in `new_aubio_notes` function within `src/notes/notes.c`.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-19802, https://github.com/aubio/aubio/commit/c5ee1307bdc004e43302abeca1802c2692b33a8e, https://github.com/aubio/aubio, https://github.com/aubio/aubio/blob/0.4.9/ChangeLog, https://github.com/pypa/advisory-database/tree/main/vulns/aubio/PYSEC-2019-164.yaml, https://lists.fedoraproject.org/archives/list/[email protected]/message/IYIKPYXZIWYWWNNORSKWRCFFCP6AFMRZ, https://lists.fedoraproject.org/archives/list/[email protected]/message/OHIRMWW4JQ6UHJK4AVBJLFRLE2TPKC2W, http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00063.html, http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00067.html, http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00003.html, http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00012.html
Affected packages
Package
Name: aubio
Purl: pkg:pypi/aubio
Affected ranges
Type: ECOSYSTEM
Events:
