The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://gitlab.com/soundtouch/soundtouch/issues/14 | third party advisory exploit |
https://github.com/TeamSeri0us/pocs/tree/master/soundtouch/2018_09_03 | third party advisory exploit |