CVE-2019-1010004
published 2019-07-15CVE-2019-1010004: SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.26%
66.3th percentile
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sox | < sox 14.4.2-2 (bookworm) | sox 14.4.2-2 (bookworm) |
| sound_exchange_project | sound_exchange | <= 14.4.2 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xr6-8qpq-x858: SoX - Sound eXchange 14
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-1010004 [HIGH] GHSA-4xr6-8qpq-x858: SoX - Sound eXchange 14
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
OSV
CVE-2019-1010004: SoX - Sound eXchange 14
osv·2019-07-15·CVSS 7.5
CVE-2019-1010004 [HIGH] CVE-2019-1010004: SoX - Sound eXchange 14
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
Red Hat
sox: OOB read in function read_samples in xa.c:219 causing denial of service
vendor_redhat·2019-07-14·CVSS 7.5
CVE-2019-1010004 [HIGH] CWE-125 sox: OOB read in function read_samples in xa.c:219 causing denial of service
sox: OOB read in function read_samples in xa.c:219 causing denial of service
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
An out-of-bounds read vulnerability was found in sox, due to insufficient validation of input data. An attacker could abuse this flaw by crafting a sound file that can cause the system to crash when read by sox or by an application using the sox library.
Statement: This issue is only a security vulnerability for applications linking against libsox, that may be caused to crash prematurely or even, under special circumstances, disclose sensitive mem
Debian
CVE-2019-1010004: sox - SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The ...
vendor_debian·2019·CVSS 7.5
CVE-2019-1010004 [HIGH] CVE-2019-1010004: sox - SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The ...
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
Scope: local
bookworm: resolved (fixed in 14.4.2-2)
bullseye: resolved (fixed in 14.4.2-2)
trixie: resolved (fixed in 14.4.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service [fedora-all]
bugzilla·2019-07-17·CVSS 5.5
CVE-2019-1010004 [MEDIUM] CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service [fedora-all]
CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service
bugzilla·2019-07-17·CVSS 5.5
CVE-2019-1010004 [MEDIUM] CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service
CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service
A vulnerability was discovered in SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file.
Reference:
https://sourceforge.net/p/sox/bugs/299/
https://sourceforge.net/p/sox/code/ci/master/tree/src/xa.c#l219
Discussion:
Created sox tracking bugs for this issue:
Affects: fedora-all [bug 1730578]
---
Statement:
This issue is only a security vulnerability for applications linking against libsox, that may be caused to crash prematurely or even, under special circumstances, disclose sensitive memory contents. Attacks against t
2019-07-15
Published