First published: Thu Jun 24 2021(Updated: )
A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/sox | <=14.4.2+git20190427-1 | 14.4.2+git20190427-1+deb10u3 14.4.2+git20190427-2+deb11u2 14.4.2+git20190427-3.5 |
Sox Project Sox | =14.4.2-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23210 is a vulnerability in the SoX software that leads to a floating point exception (divide-by-zero) and could cause an application to crash.
CVE-2021-23210 has a severity score of 5.5, which is considered medium.
CVE-2021-23210 affects SoX versions 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5, as well as 14.4.2-7 from the Sox Project.
An attacker can exploit CVE-2021-23210 by providing a crafted file to SoX, which triggers a floating point exception and crashes the application.
Yes, you can find references for CVE-2021-23210 at the following links: [Link 1](https://sourceforge.net/p/sox/bugs/351/), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1983088), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1983087).