sox

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description The Swiss Army knife of sound processing tools
Version 14.4.2+r184+gf3094754-1 [extra]

Open

Group Affected Fixed Severity Status Ticket
AVG-2100 14.4.2-7 Medium Vulnerable
Issue Group Severity Remote Type Description
CVE-2021-33844 AVG-2100 Low No Denial of service
A vulnerability was found in SoX where a divide by  zero bug exists in wav.c:967, functon startread. With a crafted wav file, the application crashes.
CVE-2021-23210 AVG-2100 Low No Denial of service
A vulnerability was found in SoX,  where a divide by zero exists in voc.c:334, functon read_samples.
CVE-2021-23172 AVG-2100 Medium No Arbitrary code execution
A vulnerability was found in SoX, where a heap overflow was found in hcom.c:161, function startread. The vulnerability is exploitable with a crafted hcomn file.
CVE-2021-23159 AVG-2100 Medium No Arbitrary code execution
A vulnerability was found in SoX, where a heap based overflow was found in  formats_i.c:376, function lsx_read_w_buf.

Resolved

Group Affected Fixed Severity Status Ticket
AVG-610 14.4.2-1 14.4.2-3 Low Fixed FS#57485
Issue Group Severity Remote Type Description
CVE-2017-18189 AVG-610 Low No Denial of service
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a...
CVE-2017-15642 AVG-610 Low No Arbitrary code execution
In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.
CVE-2017-15372 AVG-610 Low No Denial of service
There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A crafted input will lead to a...
CVE-2017-15371 AVG-610 Low No Denial of service
There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A crafted input will lead to a denial...
CVE-2017-15370 AVG-610 Low No Denial of service
There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A crafted input will lead to a denial of...
CVE-2017-11359 AVG-610 Low No Denial of service
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application...
CVE-2017-11358 AVG-610 Low No Denial of service
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows attackers to cause a denial of service (invalid memory read and application crash)...
CVE-2017-11332 AVG-610 Low No Denial of service
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows attackers to cause a denial of service (divide-by-zero error and application crash)...