Unrated severityNVD Advisory· Published Feb 15, 2018· Updated Aug 5, 2024
CVE-2017-18189
CVE-2017-18189
Description
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/sox&distro=openSUSE%20Tumbleweedpkg:rpm/suse/sox&distro=SUSE%20Package%20Hub%2012%20SP3
< 14.4.2-5.17+ 1 more
- (no CPE)range: < 14.4.2-5.17
- (no CPE)range: < 14.4.2-5.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- access.redhat.com/errata/RHSA-2019:2283mitrevendor-advisoryx_refsource_REDHAT
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62RARFRXGKPNNFFNVDV7DHJSOKAIZ3CX/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUKFZQSZG2ABMTAMOGBMY7MJNSGEIYTL/mitrevendor-advisoryx_refsource_FEDORA
- bugs.debian.org/cgi-bin/bugreport.cgimitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2019/02/msg00042.htmlmitremailing-listx_refsource_MLIST
- public-inbox.org/sox-devel/20171109114554.16297-1-mans%40mansr.com/rawmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.