CVE-2018-14523: High severity aubio vulnerability
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in newaubiopitchyinfft in pitch/pitchyinfft.c when the samplerate of the input file is larger than 50kHz.
Other sources
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in newaubiopitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-14523?
CVE-2018-14523 is a vulnerability found in the aubio package version 0.4.6.
What is the severity of CVE-2018-14523?
CVE-2018-14523 has a severity rating of 8.8 (High).
How does CVE-2018-14523 occur?
CVE-2018-14523 occurs due to a buffer over-read in the `new_aubio_pitchyinfft` function in `pitch/pitchyinfft.c` when the samplerate of the input file is larger than 50kHz in aubio version 0.4.6.
Which versions of aubio are affected by CVE-2018-14523?
Aubio version 0.4.6 is affected by CVE-2018-14523.
How can I fix CVE-2018-14523?
To fix CVE-2018-14523, update aubio to version 0.4.7 or higher.