← Vulnerability feed

Vulnerability record · CVE-2018-1000223 · published 20 August 2018

CVE-2018-1000223: Surina soundtouch memory buffer overflow vulnerability

Surina · Soundtouch

soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack appear to be exploitable via victim must open maliocius file in soundstretch utility.

8.8 CVSS 3.0 High EPSS 2.4% · top 16.4% CWE-119 · Memory buffer overflow
8.8CVSS 3.0 base score, v2 6.8
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack appear to be exploitable via victim must open maliocius file in soundstretch utility.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gitlab.com/soundtouch/soundtouch/issues/6 ExploitIssue TrackingThird Party Advisory
https://gitlab.com/soundtouch/soundtouch/issues/6 ExploitIssue TrackingThird Party Advisory

Track CVE-2018-1000223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-17097Surina soundtouch double free vulnerabilityThe WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly…EPSS 2.8%8.8CVE-2018-17098Surina soundtouch out-of-bounds write vulnerabilityThe WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from siz…EPSS 2.8%7.5CVE-2018-14044Surina soundtouch vulnerabilityThe RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause …EPSS 2.6%7.5CVE-2018-14045Surina soundtouch vulnerabilityThe FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a …EPSS 2.6%6.5CVE-2018-17096Surina soundtouch vulnerabilityThe BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (asser…EPSS 2.3%5.5CVE-2017-9258Surina soundtouch vulnerabilityThe TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (i…EPSS 4.2%5.5CVE-2017-9259Surina soundtouch uncontrolled resource consumption vulnerabilityThe TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of se…EPSS 6.2%5.5CVE-2017-9260Surina soundtouch out-of-bounds read vulnerabilityThe TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of serv…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2018-1000223), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.