CVE Vulnerabilities

CVE-2017-9258

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jul 27, 2017 | Modified: Oct 03, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Soundtouch Surina 1.9.2 (including) 1.9.2 (including)
Soundtouch Ubuntu artful *
Soundtouch Ubuntu trusty *
Soundtouch Ubuntu trusty/esm *
Soundtouch Ubuntu upstream *
Soundtouch Ubuntu xenial *
Soundtouch Ubuntu zesty *

References