CVE-2023-26590: Floating point exception in src/aiff.c
A floating point exception vulnerability was found in sox, in the lsxaiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
Other sources
A vulnerabilty was found in sox v14.4.3, Floating Point Exception vulnerability that exists in the lsxaiffstartwrite function at sox/src/aiff.c:622:58. This vulnerability could lead to security issues such as denial of service.
References: https://sourceforge.net/p/sox/bugs/370/.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26590?
CVE-2023-26590 is a floating point exception vulnerability found in sox, which can lead to a denial of service.
What is the severity of CVE-2023-26590?
The severity of CVE-2023-26590 is medium (5.5).
How can the CVE-2023-26590 vulnerability affect me?
The CVE-2023-26590 vulnerability can lead to a denial of service if exploited.
Which software versions are affected by CVE-2023-26590?
Sox version 14.4.3 and Extra Packages for Enterprise Linux version 8.0 are affected by CVE-2023-26590.
How can I fix the CVE-2023-26590 vulnerability?
Updating to the latest version of sox (version 14.4.4) or Extra Packages for Enterprise Linux (version 8.1) will fix the CVE-2023-26590 vulnerability.