id: PYSEC-2018-63 details: An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes. affected: - package: name: aubio ecosystem: PyPI purl: pkg:pypi/aubio ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.4.7 versions: - 0.4.3 - 0.4.3.post1 - 0.4.3a1 - 0.4.3a2 - 0.4.4 - 0.4.5 - 0.4.6 references: - type: REPORT url: https://github.com/aubio/aubio/issues/189 - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00031.html - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00071.html - type: ADVISORY url: https://github.com/advisories/GHSA-3x58-8qmv-wqw5 aliases: - CVE-2018-14523 - GHSA-3x58-8qmv-wqw5 modified: "2021-08-25T04:29:55.843499Z" published: "2018-07-23T08:29:00Z"