The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://gitlab.com/soundtouch/soundtouch/issues/14 | third party advisory exploit |
https://github.com/TeamSeri0us/pocs/blob/master/soundtouch/2018_09_03 | third party advisory exploit |