See how aubio compares to other vendors in security performance
aubio v0.4.0 to v0.4.8 has a Buffer Overflow in newaubiotempo.
aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in newaubiofilterbank via invalid nfilters.
aubio v0.4.0 to v0.4.8 has a newaubioonset NULL pointer dereference in newaubionotes function within src/notes/notes.c.
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubiosourceavcodecreadframe in io/sourceavcodec.c, as demonstrated by aubiomfcc.
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubiopitchsetunit in pitch/pitch.c, as demonstrated by aubionotes.
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in newaubiopitchyinfft in pitch/pitchyinfft.c when the samplerate of the input file is larger than 50kHz.
A NULL pointer dereference (DoS) Vulnerability was found in the function aubiosourceavcodecreadframe in io/sourceavcodec.c of aubio, which may lead to DoS when playing a crafted audio file.
The swriaudioconvert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.
In aubio 0.4.6, a divide-by-zero error exists in the function newaubiosourcewavread() in sourcewavread.c, which may lead to DoS when playing a crafted audio file.