cbcvebase.

Debian Sox vulnerabilities

28 known vulnerabilities affecting debian/sox.

Total CVEs
28
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM18LOW2

Vulnerabilities

Page 2 of 2
CVE-2019-1010004P4HIGHCVSS 7.5fixed in sox 14.4.2-2 (bookworm)2019
CVE-2019-1010004 [HIGH] CVE-2019-1010004: sox - SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The ... SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189. Scope: local bookworm: resolved (fixed in 14.4.2-2) bullseye: resolved (fixed in 14.4.2-2) trixie:
debian
CVE-2022-31651P4MEDIUMCVSS 5.5fixed in sox 14.4.2+git20190427-3.1 (bookworm)2022
CVE-2022-31651 [MEDIUM] CVE-2022-31651: sox - In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a. In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a. Scope: local bookworm: resolved (fixed in 14.4.2+git20190427-3.1) bullseye: resolved (fixed in 14.4.2+git20190427-2+deb11u1) trixie: resolved (fixed in 14.4.2+git20190427-3.1)
debian
CVE-2019-13590P4LOWCVSS 5.5fixed in sox 14.4.2+git20190427-2 (bookworm)2019
CVE-2019-13590 [MEDIUM] CVE-2019-13590: sox - An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread funct... An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior check that it is a valid pointer, leading to a NULL pointer dereference on lsx_readbuf in form
debian
CVE-2022-31650P4MEDIUMCVSS 5.5fixed in sox 14.4.2+git20190427-3.1 (bookworm)2022
CVE-2022-31650 [MEDIUM] CVE-2022-31650: sox - In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff... In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a. Scope: local bookworm: resolved (fixed in 14.4.2+git20190427-3.1) bullseye: resolved (fixed in 14.4.2+git20190427-2+deb11u1) trixie: resolved (fixed in 14.4.2+git20190427-3.1)
debian
CVE-2021-23159P4MEDIUMCVSS 5.5fixed in sox 14.4.2+git20190427-3.2 (bookworm)2021
CVE-2021-23159 [MEDIUM] CVE-2021-23159: sox - A vulnerability was found in SoX, where a heap-buffer-overflow occurs in functio... A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash. Scope: local bookworm: resolved (fixed in 14.4.2+git20190427-3.2) bullseye: resolved (fixed in 14.4.2+git20190427-2+deb11u1) trixie: resolved (fixed in 14
debian
CVE-2021-23172P4MEDIUMCVSS 5.5fixed in sox 14.4.2+git20190427-3.2 (bookworm)2021
CVE-2021-23172 [MEDIUM] CVE-2021-23172: sox - A vulnerability was found in SoX, where a heap-buffer-overflow occurs in functio... A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash. Scope: local bookworm: resolved (fixed in 14.4.2+git20190427-3.2) bullseye: resolved (fixed in 14.4.2+git20190427-2+deb11u1) trixie: resolved (fixed in 14.4.2
debian
CVE-2021-23210P4MEDIUMCVSS 5.5fixed in sox 14.4.2+git20190427-3.2 (bookworm)2021
CVE-2021-23210 [MEDIUM] CVE-2021-23210: sox - A floating point exception (divide-by-zero) issue was discovered in SoX in funct... A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash. Scope: local bookworm: resolved (fixed in 14.4.2+git20190427-3.2) bullseye: resolved (fixed in 14.4.2+git20190427-2+deb11u1) trixie: resolved (fixed in 14.4.2+git20190427-3.2)
debian
CVE-2021-33844P4MEDIUMCVSS 5.5fixed in sox 14.4.2+git20190427-3.1 (bookworm)2021
CVE-2021-33844 [MEDIUM] CVE-2021-33844: sox - A floating point exception (divide-by-zero) issue was discovered in SoX in funct... A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash. Scope: local bookworm: resolved (fixed in 14.4.2+git20190427-3.1) bullseye: resolved (fixed in 14.4.2+git20190427-2+deb11u1) trixie: resolved (fixed in 14.4.2+git20190427-3.1)
debian
Debian Sox vulnerabilities | cvebase