CVE-2017-18189
published 2018-02-15CVE-2017-18189: In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
5.15%
91.5th percentile
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sox | < sox 14.4.2-2 (bookworm) | sox 14.4.2-2 (bookworm) |
| sound_exchange_project | sound_exchange | <= 14.4.2 | — |
| sourceforge | sox_sound_exchange | — | — |
| sourceforge | sox_sound_exchange | >= 0 < 14.4.2-2 | 14.4.2-2 |
| sourceforge | sox_sound_exchange | >= 0 < 14.4.2-2 | 14.4.2-2 |
| sourceforge | sox_sound_exchange | >= 0 < 14.4.2-2 | 14.4.2-2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xr6-8qpq-x858: SoX - Sound eXchange 14
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-1010004 [HIGH] GHSA-4xr6-8qpq-x858: SoX - Sound eXchange 14
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
GHSA
GHSA-7cwr-p3p4-jp5x: In the startread function in xa
ghsa_unreviewed·2022-05-13
CVE-2017-18189 [HIGH] CWE-476 GHSA-7cwr-p3p4-jp5x: In the startread function in xa
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
OSV
CVE-2019-1010004: SoX - Sound eXchange 14
osv·2019-07-15·CVSS 7.5
CVE-2019-1010004 [HIGH] CVE-2019-1010004: SoX - Sound eXchange 14
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
OSV
CVE-2017-18189: In the startread function in xa
osv·2018-02-15·CVSS 7.5
CVE-2017-18189 [HIGH] CVE-2017-18189: In the startread function in xa
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
Red Hat
sox: OOB read in function read_samples in xa.c:219 causing denial of service
vendor_redhat·2019-07-14·CVSS 7.5
CVE-2019-1010004 [HIGH] CWE-125 sox: OOB read in function read_samples in xa.c:219 causing denial of service
sox: OOB read in function read_samples in xa.c:219 causing denial of service
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
An out-of-bounds read vulnerability was found in sox, due to insufficient validation of input data. An attacker could abuse this flaw by crafting a sound file that can cause the system to crash when read by sox or by an application using the sox library.
Statement: This issue is only a security vulnerability for applications linking against libsox, that may be caused to crash prematurely or even, under special circumstances, disclose sensitive mem
Debian
CVE-2019-1010004: sox - SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The ...
vendor_debian·2019·CVSS 7.5
CVE-2019-1010004 [HIGH] CVE-2019-1010004: sox - SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The ...
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
Scope: local
bookworm: resolved (fixed in 14.4.2-2)
bullseye: resolved (fixed in 14.4.2-2)
trixie: resolved (fixed in 14.4.2-2)
Red Hat
sox: NULL pointer dereference in startread function in xa.c
vendor_redhat·2018-02-15·CVSS 7.5
CVE-2017-18189 [HIGH] CWE-119 sox: NULL pointer dereference in startread function in xa.c
sox: NULL pointer dereference in startread function in xa.c
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
A NULL pointer dereference flaw found in the way SoX handled processing of AIFF files. An attacker could potentially use this flaw to crash the SoX application by tricking it into processing crafted AIFF files.
Package: sox (Red Hat Enterprise Linux 5) - Not affected
Package: sox (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2017-18189: sox - In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corr...
vendor_debian·2017·CVSS 7.5
CVE-2017-18189 [HIGH] CVE-2017-18189: sox - In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corr...
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
Scope: local
bookworm: resolved (fixed in 14.4.2-2)
bullseye: resolved (fixed in 14.4.2-2)
trixie: resolved (fixed in 14.4.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18189 sox: NULL pointer dereference in startread function in xa.c
bugzilla·2018-02-15·CVSS 7.5
CVE-2017-18189 [HIGH] CVE-2017-18189 sox: NULL pointer dereference in startread function in xa.c
CVE-2017-18189 sox: NULL pointer dereference in startread function in xa.c
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers a NULL pointer dereference, which may allow an attacker to cause denial-of-service via a specially crafted file.
External References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121
Patch:
https://public-inbox.org/sox-devel/[email protected]/raw
Discussion:
Created sox tracking bugs for this issue:
Affects: fedora-all [bug 1545867]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2283 https://access.redhat.com/errata/RHSA-2019:2283
---
This bug is now closed. Further updates for individual products
Bugzilla
CVE-2017-18189 sox: Null pointer dereference in startread function in xa.c [fedora-all]
bugzilla·2018-02-15·CVSS 7.5
CVE-2017-18189 [HIGH] CVE-2017-18189 sox: Null pointer dereference in startread function in xa.c [fedora-all]
CVE-2017-18189 sox: Null pointer dereference in startread function in xa.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
https://access.redhat.com/errata/RHSA-2019:2283https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121https://lists.debian.org/debian-lts-announce/2019/02/msg00042.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62RARFRXGKPNNFFNVDV7DHJSOKAIZ3CX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUKFZQSZG2ABMTAMOGBMY7MJNSGEIYTL/https://public-inbox.org/sox-devel/20171109114554.16297-1-mans%40mansr.com/rawhttps://access.redhat.com/errata/RHSA-2019:2283https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121https://lists.debian.org/debian-lts-announce/2019/02/msg00042.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62RARFRXGKPNNFFNVDV7DHJSOKAIZ3CX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUKFZQSZG2ABMTAMOGBMY7MJNSGEIYTL/https://public-inbox.org/sox-devel/20171109114554.16297-1-mans%40mansr.com/raw
2018-02-15
Published