CVE-2018-14523 (NVD)

2018-07-23

An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.

Products Aubio, Leap, Linux_enterprise
Type Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
First patch - None (likely due to unavailable code)
Links http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00031.html
https://github.com/aubio/aubio/issues/189
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00071.html