An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
https://github.com/aubio/aubio/issues/189
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00071.html
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00031.html