CVE-2017-11332: Divide by Zero
Published Jul 31, 2017
·Updated
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
Affected Software
3 affected components
Sound Exchange Project Sound Exchange=14.4.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Jul 31, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11332?
CVE-2017-11332 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2017-11332?
To mitigate CVE-2017-11332, update Sound eXchange to version 14.4.3 or later.
3
Which versions of Sound eXchange are affected by CVE-2017-11332?
CVE-2017-11332 affects Sound eXchange version 14.4.2.
4
Can CVE-2017-11332 be exploited remotely?
Yes, CVE-2017-11332 can be exploited remotely through specially crafted wav files.
5
What type of attack does CVE-2017-11332 enable?
CVE-2017-11332 allows attackers to cause a divide-by-zero error leading to application crashes.