First published: Thu Jun 24 2021(Updated: )
A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/sox | <=14.4.2+git20190427-1 | 14.4.2+git20190427-1+deb10u3 14.4.2+git20190427-2+deb11u2 14.4.2+git20190427-3.5 |
Sox Project Sox | =14.4.2-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33844 is a floating point exception (divide-by-zero) vulnerability discovered in SoX, specifically in the function startread() of the wav.c file.
The severity of CVE-2021-33844 is medium with a severity value of 5.5.
CVE-2021-33844 affects SoX versions 14.4.2+git20190427-1+deb10u3, 14.4.2+git20190427-2+deb11u2, and 14.4.2+git20190427-3.5.
An attacker with a crafted WAV file can exploit CVE-2021-33844 to cause an application crash.
You can find more information about CVE-2021-33844 at the following references: [1] [2] [3].