CVE-2019-1010004: Medium severity sound exchange vulnerability
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: readsamples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1010004?
CVE-2019-1010004 is a vulnerability in SoX - Sound eXchange 14.4.2 and earlier that allows for an out-of-bounds read.
What is the impact of CVE-2019-1010004?
The impact of CVE-2019-1010004 is a denial of service.
How does CVE-2019-1010004 work?
CVE-2019-1010004 occurs in the read_samples function at xa.c:219 when a victim opens a specially crafted .xa file.
How severe is CVE-2019-1010004?
CVE-2019-1010004 has a severity rating of medium.
Is there a fix for CVE-2019-1010004?
No official fix has been released for CVE-2019-1010004 at the moment. It is recommended to update to the latest version of SoX when it becomes available.