CVE-2021-33844: Divide by Zero
A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.
Other sources
A vulnerability was found in SoX where a divide by zero bug in wav.c:967, functon startread. With crafted wav file, it crashes.
References: https://sourceforge.net/p/sox/bugs/349/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33844?
CVE-2021-33844 is a floating point exception (divide-by-zero) vulnerability discovered in SoX, specifically in the function startread() of the wav.c file.
What is the severity of CVE-2021-33844?
The severity of CVE-2021-33844 is medium with a severity value of 5.5.
How does CVE-2021-33844 affect SoX?
CVE-2021-33844 affects SoX versions 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5.
How can an attacker exploit CVE-2021-33844?
An attacker with a crafted WAV file can exploit CVE-2021-33844 to cause an application crash.
Where can I find more information about CVE-2021-33844?
You can find more information about CVE-2021-33844 at the following references: [1] [2] [3].