CVE-2021-40426: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the sphere.c startread() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40426?
CVE-2021-40426 is classified as a critical vulnerability due to its potential for exploitation via heap-based buffer overflow.
How do I fix CVE-2021-40426?
To fix CVE-2021-40426, update to the patched versions of the affected packages, such as sox 14.4.2+git20190427-2+deb11u2 or later.
Which software is affected by CVE-2021-40426?
CVE-2021-40426 affects Sound Exchange libsox versions 14.4.2 and specific Debian packages built on this version.
What causes CVE-2021-40426?
CVE-2021-40426 is caused by a heap-based buffer overflow in the start_read() function of sphere.c in the vulnerable software.
How can an attacker exploit CVE-2021-40426?
An attacker can exploit CVE-2021-40426 by supplying a specially-crafted file designed to trigger the heap buffer overflow.