The swriaudioconvert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.
{
"binaries": [
{
"binary_version": "0.4.1-2build4",
"binary_name": "aubio-tools"
},
{
"binary_version": "0.4.1-2build4",
"binary_name": "libaubio-dev"
},
{
"binary_version": "0.4.1-2build4",
"binary_name": "libaubio4"
},
{
"binary_version": "0.4.1-2build4",
"binary_name": "python-aubio"
}
]
}
{
"binaries": [
{
"binary_version": "0.4.5-1build1",
"binary_name": "aubio-tools"
},
{
"binary_version": "0.4.5-1build1",
"binary_name": "libaubio-dev"
},
{
"binary_version": "0.4.5-1build1",
"binary_name": "libaubio5"
},
{
"binary_version": "0.4.5-1build1",
"binary_name": "python-aubio"
},
{
"binary_version": "0.4.5-1build1",
"binary_name": "python3-aubio"
}
]
}