cbcvebase.
CVE-2014-8145
published 2014-12-31

CVE-2014-8145: Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansox< sox 14.4.2-2 (bookworm)sox 14.4.2-2 (bookworm)
oraclesolaris
sound_exchange_projectsound_exchange<= 14.4.1

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH