CVE-2021-23172: Medium severity sox (sound exchange) vulnerability
A vulnerability was found in SoX where, a heap overflow in hcom.c:161. Function startread with crafted hcomn file the vulnerability is exploitable.
References: https://sourceforge.net/p/sox/bugs/350/
Other sources
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23172?
CVE-2021-23172 is a vulnerability found in SoX, where a heap-buffer-overflow occurs in the function startread() in the hcom.c file.
How severe is CVE-2021-23172?
The severity of CVE-2021-23172 is high with a CVSS score of 5.5.
How does CVE-2021-23172 affect SoX?
CVE-2021-23172 affects SoX by causing a heap-buffer-overflow in the startread() function, which can lead to a crash of the application.
Which versions of SoX are affected by CVE-2021-23172?
The versions affected by CVE-2021-23172 are 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5.
How can I mitigate CVE-2021-23172 in SoX?
To mitigate CVE-2021-23172 in SoX, it is recommended to update to version 14.4.2+git20190427-1 or later.