First published: Thu Jun 24 2021(Updated: )
A vulnerability was found in SoX where, a heap overflow in hcom.c:161. Function startread with crafted hcomn file the vulnerability is exploitable. References: <a href="https://sourceforge.net/p/sox/bugs/350/">https://sourceforge.net/p/sox/bugs/350/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/sox | <=14.4.2+git20190427-1 | 14.4.2+git20190427-1+deb10u3 14.4.2+git20190427-2+deb11u2 14.4.2+git20190427-3.5 |
Sox Project Sox | =14.4.2-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23172 is a vulnerability found in SoX, where a heap-buffer-overflow occurs in the function startread() in the hcom.c file.
The severity of CVE-2021-23172 is high with a CVSS score of 5.5.
CVE-2021-23172 affects SoX by causing a heap-buffer-overflow in the startread() function, which can lead to a crash of the application.
The versions affected by CVE-2021-23172 are 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5.
To mitigate CVE-2021-23172 in SoX, it is recommended to update to version 14.4.2+git20190427-1 or later.