An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.
{
"binaries": [
{
"binary_name": "faust",
"binary_version": "2.70.3+ds-1.1build2"
},
{
"binary_name": "faust-common",
"binary_version": "2.70.3+ds-1.1build2"
},
{
"binary_name": "libfaust-static",
"binary_version": "2.70.3+ds-1.1build2"
},
{
"binary_name": "libfaust2t64",
"binary_version": "2.70.3+ds-1.1build2"
}
]
}{
"binaries": [
{
"binary_name": "faust",
"binary_version": "2.77.3+ds-2"
},
{
"binary_name": "faust-common",
"binary_version": "2.77.3+ds-2"
},
{
"binary_name": "libfaust-static",
"binary_version": "2.77.3+ds-2"
},
{
"binary_name": "libfaust2t64",
"binary_version": "2.77.3+ds-2"
}
]
}{
"binaries": [
{
"binary_name": "faust",
"binary_version": "2.79.3+ds-2ubuntu1"
},
{
"binary_name": "faust-common",
"binary_version": "2.79.3+ds-2ubuntu1"
},
{
"binary_name": "libfaust-static",
"binary_version": "2.79.3+ds-2ubuntu1"
},
{
"binary_name": "libfaust2t64",
"binary_version": "2.79.3+ds-2ubuntu1"
}
]
}