CVE-2017-11359: Divide by Zero
Published Jul 31, 2017
·Updated
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
Affected Software
3 affected components
Sound Exchange Project Sound Exchange=14.4.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Jul 31, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11359?
CVE-2017-11359 has a medium severity rating as it can lead to a denial of service due to a divide-by-zero error.
2
How do I fix CVE-2017-11359?
To fix CVE-2017-11359, upgrade to SoX version 14.4.2 or apply any available patches provided by your distribution.
3
Which versions of SoX are affected by CVE-2017-11359?
SoX version 14.4.2 is specifically affected by CVE-2017-11359.
4
What type of attack does CVE-2017-11359 enable?
CVE-2017-11359 enables a denial of service attack through a crafted snd file.
5
Who can be affected by CVE-2017-11359?
Users of SoX version 14.4.2, particularly on Debian Linux 7.0 and 8.0, can be affected by CVE-2017-11359.