cbcvebase.
CVE-2017-18189
published 2018-02-15

CVE-2017-18189: In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansox< sox 14.4.2-2 (bookworm)sox 14.4.2-2 (bookworm)
sound_exchange_projectsound_exchange<= 14.4.2
sourceforgesox_sound_exchange
sourceforgesox_sound_exchange>= 0 < 14.4.2-214.4.2-2
sourceforgesox_sound_exchange>= 0 < 14.4.2-214.4.2-2
sourceforgesox_sound_exchange>= 0 < 14.4.2-214.4.2-2

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH