id: PYSEC-2019-164 details: aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference. affected: - package: name: aubio ecosystem: PyPI purl: pkg:pypi/aubio ranges: - type: ECOSYSTEM events: - introduced: 0.4.0 - fixed: 0.4.9 versions: - 0.4.3 - 0.4.3.post1 - 0.4.3a1 - 0.4.3a2 - 0.4.4 - 0.4.5 - 0.4.6 - 0.4.7 - 0.4.8 references: - type: WEB url: https://github.com/aubio/aubio/blob/0.4.9/ChangeLog - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00063.html - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00067.html - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00003.html - type: WEB url: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYIKPYXZIWYWWNNORSKWRCFFCP6AFMRZ/ - type: WEB url: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OHIRMWW4JQ6UHJK4AVBJLFRLE2TPKC2W/ - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00012.html - type: ADVISORY url: https://github.com/advisories/GHSA-c6jq-h4jp-72pr aliases: - CVE-2018-19802 - GHSA-c6jq-h4jp-72pr modified: '2021-08-25T04:29:55.989477Z' published: '2019-06-07T17:29:00Z'