CVE-2021-23210: Divide by Zero
A floating point exception (divide-by-zero) issue was discovered in SoX in functon readsamples() of voc.c file. An attacker with a crafted file, could cause an application to crash.
Other sources
A vulnerability was found in SoX where, a divide by zero in voc.c:334, functon readsamples
References: https://sourceforge.net/p/sox/bugs/351/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23210?
CVE-2021-23210 is a vulnerability in the SoX software that leads to a floating point exception (divide-by-zero) and could cause an application to crash.
How severe is CVE-2021-23210?
CVE-2021-23210 has a severity score of 5.5, which is considered medium.
How does CVE-2021-23210 affect SoX?
CVE-2021-23210 affects SoX versions 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5, as well as 14.4.2-7 from the Sox Project.
How can an attacker exploit CVE-2021-23210?
An attacker can exploit CVE-2021-23210 by providing a crafted file to SoX, which triggers a floating point exception and crashes the application.
Are there any known references for CVE-2021-23210?
Yes, you can find references for CVE-2021-23210 at the following links: [Link 1](https://sourceforge.net/p/sox/bugs/351/), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1983088), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1983087).