Unrated severityNVD Advisory· Published Feb 15, 2019· Updated Aug 4, 2024
CVE-2019-8354
CVE-2019-8354
Description
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- usn.ubuntu.com/4079-1/mitrevendor-advisoryx_refsource_UBUNTU
- usn.ubuntu.com/4079-2/mitrevendor-advisoryx_refsource_UBUNTU
- lists.debian.org/debian-lts-announce/2019/05/msg00040.htmlmitremailing-listx_refsource_MLIST
- sourceforge.net/p/sox/bugs/319mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.