CVE-2023-34432: Heap-buffer-overflow in src/formats_i.c
A heap buffer overflow vulnerability was found in sox, in the lsxreadbuf function at sox/src/formatsi.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
Other sources
A vulnerabilty was found in sox v14.4.3, heap-buffer-overflow vulnerability that exists in the lsxreadbuf function at sox/src/formatsi.c:98:16. This vulnerability could lead to security issues such as denial of service, code execution, or information disclosure.
References: https://sourceforge.net/p/sox/bugs/367/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-34432?
CVE-2023-34432 is a heap buffer overflow vulnerability found in sox.
How does CVE-2023-34432 impact the affected software?
CVE-2023-34432 can lead to a denial of service, code execution, or information disclosure.
Which software is affected by CVE-2023-34432?
The affected software includes Sound Exchange Project Sound Exchange, Redhat Enterprise Linux versions 6.0 and 7.0, Fedoraproject Extra Packages For Enterprise Linux version 8.0, and Fedoraproject Fedora version 38.
What is the severity level of CVE-2023-34432?
CVE-2023-34432 has a severity level of 7 (high).
How can I fix CVE-2023-34432?
To fix CVE-2023-34432, it is recommended to update the affected software to a version that has addressed the vulnerability.