Advisories for Pypi/Aubio package

2019
2018

Out-of-bounds Read

An issue was discovered in aubio. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.

2017

NULL Pointer Dereference

A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avcodec.c of aubio, which may lead to DoS when playing a crafted audio file.

NULL Pointer Dereference

The swri_audio_convert function in audioconvert.c in FFmpeg libswresample, as used in FFmpeg, aubio, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.

Divide By Zero

A divide-by-zero error exists in the function new_aubio_source_wavread() in source_wavread.c, which may lead to DoS when playing a crafted audio file.