CVE-2017-11359
published 2017-07-31CVE-2017-11359: The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application…
PriorityP424medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EXPLOIT
EPSS
6.60%
93.1th percentile
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sox | < sox 14.4.2-2 (bookworm) | sox 14.4.2-2 (bookworm) |
| sound_exchange_project | sound_exchange | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcrg-ppmg-4fm2: The wavwritehdr function in wav
ghsa_unreviewed·2022-05-14
CVE-2017-11359 [MEDIUM] CWE-369 GHSA-qcrg-ppmg-4fm2: The wavwritehdr function in wav
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
OSV
CVE-2017-11359: The wavwritehdr function in wav
osv·2017-07-31·CVSS 5.5
CVE-2017-11359 [MEDIUM] CVE-2017-11359: The wavwritehdr function in wav
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
Red Hat
sox: Devide by zero in wavwritehdr function in wav.c
vendor_redhat·2017-07-30·CVSS 5.5
CVE-2017-11359 [MEDIUM] CWE-369 sox: Devide by zero in wavwritehdr function in wav.c
sox: Devide by zero in wavwritehdr function in wav.c
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
Package: sox (Red Hat Enterprise Linux 5) - Will not fix
Package: sox (Red Hat Enterprise Linux 6) - Will not fix
Package: sox (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-11359: sox - The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote a...
vendor_debian·2017·CVSS 5.5
CVE-2017-11359 [MEDIUM] CVE-2017-11359: sox - The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote a...
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
Scope: local
bookworm: resolved (fixed in 14.4.2-2)
bullseye: resolved (fixed in 14.4.2-2)
trixie: resolved (fixed in 14.4.2-2)
No detection rules found.
Bugzilla
CVE-2017-11359 sox: Devide by zero in wavwritehdr function in wav.c
bugzilla·2017-08-11·CVSS 5.5
CVE-2017-11359 [MEDIUM] CVE-2017-11359 sox: Devide by zero in wavwritehdr function in wav.c
CVE-2017-11359 sox: Devide by zero in wavwritehdr function in wav.c
A flaw was found in sox 14.4.2. The wavwritehdr function in wav.c in Sound eXchange(SoX) 14.4.2 allows remote attackers to cause a denial of
service(divide-by-zero error and application crash) via a crafted snd file which convert to wav file.
References:
http://seclists.org/fulldisclosure/2017/Jul/81
Discussion:
Created sox tracking bugs for this issue:
Affects: fedora-all [bug 1480678]
Bugzilla
CVE-2017-11332 CVE-2017-11358 CVE-2017-11359 sox: various flaws [fedora-all]
bugzilla·2017-08-11·CVSS 5.5
CVE-2017-11332 [MEDIUM] CVE-2017-11332 CVE-2017-11358 CVE-2017-11359 sox: various flaws [fedora-all]
CVE-2017-11332 CVE-2017-11358 CVE-2017-11359 sox: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Wiz
CVE-2022-50798 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2022-50798 [MEDIUM] CVE-2022-50798 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50798 :
Linux Debian vulnerability analysis and mitigation
Rejected reason: This candidate is a duplicate of CVE-2017-11359.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Debian
Echo
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
sox
Sources
NVD
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Dec 31, 2025
Echo Severity HIGH Has Fix Added at: Dec 31, 2025
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Debian vulnerabilities:
CVE ID
Severity
http://seclists.org/fulldisclosure/2017/Jul/81https://lists.debian.org/debian-lts-announce/2017/11/msg00043.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00007.htmlhttps://security.gentoo.org/glsa/201810-02https://www.exploit-db.com/exploits/42398/http://seclists.org/fulldisclosure/2017/Jul/81https://lists.debian.org/debian-lts-announce/2017/11/msg00043.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00007.htmlhttps://security.gentoo.org/glsa/201810-02https://www.exploit-db.com/exploits/42398/
2017-07-31
Published