CVE-2021-23159: Medium severity Sox Project Sox vulnerability
A vulnerability was found in SoX, where a heap based overflow was found in formatsi.c:376, function lsxreadwbuf.
References: https://sourceforge.net/p/sox/bugs/352/
Other sources
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsxreadwbuf() in formatsi.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23159?
CVE-2021-23159 is a vulnerability in SoX where a heap-buffer-overflow occurs in the lsx_read_w_buf() function in the formats_i.c file, which can lead to an application crash.
What is the severity of CVE-2021-23159?
CVE-2021-23159 has a severity rating of 5.5 (high).
How can CVE-2021-23159 be exploited?
CVE-2021-23159 can be exploited by using a crafted file that triggers the heap-buffer-overflow in SoX's lsx_read_w_buf() function.
Which software versions are affected by CVE-2021-23159?
SoX versions 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5 are affected by CVE-2021-23159.
Where can I find more information about CVE-2021-23159?
You can find more information about CVE-2021-23159 at the following references: [Link 1](https://security-tracker.debian.org/tracker/CVE-2021-23159), [Link 2](https://sourceforge.net/p/sox/bugs/352/), [Link 3](https://bugzilla.redhat.com/show_bug.cgi?id=1975671).