An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/aubio/aubio/issues/189 | third party advisory exploit |
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00031.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00071.html | vendor advisory |