rpm package
suse/sox&distro=SUSE Package Hub 12 SP3
pkg:rpm/suse/sox&distro=SUSE%20Package%20Hub%2012%20SP3
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-18189 | — | < 14.4.2-5.1 | 14.4.2-5.1 | Feb 15, 2018 | In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service. | ||
| CVE-2017-15642 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Oct 19, 2017 | In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file. | |
| CVE-2017-15372 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Oct 16, 2017 | There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. | |
| CVE-2017-15371 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Oct 16, 2017 | There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. | |
| CVE-2017-15370 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Oct 16, 2017 | There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. | |
| CVE-2017-11359 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Jul 31, 2017 | The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file. | |
| CVE-2017-11358 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Jul 31, 2017 | The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file. | |
| CVE-2017-11332 | Med | 5.5 | < 14.4.2-5.1 | 14.4.2-5.1 | Jul 31, 2017 | The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file. |
- CVE-2017-18189Feb 15, 2018affected < 14.4.2-5.1fixed 14.4.2-5.1
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.
- affected < 14.4.2-5.1fixed 14.4.2-5.1
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.