{"affected":[{"ecosystem_specific":{"binaries":[{"libSoundTouch0":"1.8.0-3.6.1","soundtouch-devel":"1.8.0-3.6.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"soundtouch","purl":"pkg:rpm/suse/soundtouch&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.8.0-3.6.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for soundtouch fixes the following issues:\n\n- CVE-2018-17098: The WavFileBase class allowed remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. (bsc#1108632) \n- CVE-2018-17097: The WavFileBase class allowed remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch. (double free) (bsc#1108631) \n- CVE-2018-17096: The BPMDetect class allowed remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch. (bsc#1108630) \n","id":"SUSE-SU-2018:3610-1","modified":"2018-11-02T16:10:34Z","published":"2018-11-02T16:10:34Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183610-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108630"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108631"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-17096"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-17097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-17098"}],"related":["CVE-2018-17096","CVE-2018-17097","CVE-2018-17098"],"summary":"Security update for soundtouch","upstream":["CVE-2018-17096","CVE-2018-17097","CVE-2018-17098"]}