CVE-2017-9260: Surina Soundtouch

Medium severity, CVSS 5.5. EPSS: 3.9% chance of exploitation in the next 30 days.

The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file.

Affected products

  • Surina Soundtouch: version 1.9.2 only

Published 2017-07-27. Last modified 2026-06-17.