CVE-2014-8145: Buffer Overflow
Published Dec 31, 2014
·Updated
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) startread or (2) AdpcmReadBlock function.
Affected Software
4 affected components
Sound Exchange Project Sound Exchange<=14.4.1
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Oracle Solaris=11.2
Event History
Dec 31, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8145?
CVE-2014-8145 has a high severity rating due to multiple heap-based buffer overflows that can lead to remote code execution.
2
What versions of SoX are affected by CVE-2014-8145?
CVE-2014-8145 affects Sound eXchange (SoX) version 14.4.1 and earlier.
3
How do I fix CVE-2014-8145?
To fix CVE-2014-8145, upgrade to SoX version 14.4.2 or later which contains patches for this vulnerability.
4
What exploits are possible with CVE-2014-8145?
CVE-2014-8145 allows remote attackers to execute arbitrary code through crafted WAV files.
5
Which operating systems are impacted by CVE-2014-8145?
CVE-2014-8145 impacts Debian 7.0, Debian 8.0, and Oracle Solaris 11.2 among others.