CVE-2017-11358: Medium severity Sound Exchange Project Sound Exchange vulnerability
Published Jul 31, 2017
·Updated
The readsamples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.
Affected Software
4 affected componentsFixes available
debian/sox
14.4.2+git20190427-114.4.2+git20190427-1+deb10u314.4.2+git20190427-2+deb11u214.4.2+git20190427-3.5
Sound Exchange Project Sound Exchange=14.4.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Jul 31, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11358?
CVE-2017-11358 has a severity rating that indicates it can cause a denial of service due to an invalid memory read.
2
What software is affected by CVE-2017-11358?
The vulnerability CVE-2017-11358 affects Sound eXchange (SoX) version 14.4.2 and certain Debian packages that include this version.
3
How do I fix CVE-2017-11358?
To resolve CVE-2017-11358, update SoX to a version later than 14.4.2, especially within the Debian distributions.
4
Can CVE-2017-11358 be exploited remotely?
Yes, CVE-2017-11358 can be exploited by remote attackers through crafted hcom files.
5
What type of attack does CVE-2017-11358 enable?
CVE-2017-11358 enables a denial of service attack, leading to application crashes.