REDHAT-BUG-1545866: Null Pointer Dereference
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers a NULL pointer dereference, which may allow an attacker to cause denial-of-service via a specially crafted file.
External References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121
Patch:
https://public-inbox.org/sox-devel/20171109114554.16297-1-mans@mansr.com/raw
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1545866?
The severity of REDHAT-BUG-1545866 is classified as a denial-of-service vulnerability.
How do I fix REDHAT-BUG-1545866?
To fix REDHAT-BUG-1545866, it is recommended to update to a version of SoX later than 14.4.2 that addresses this issue.
What causes the vulnerability REDHAT-BUG-1545866?
The vulnerability REDHAT-BUG-1545866 is caused by a NULL pointer dereference triggered by a corrupt header specifying zero channels in a specially crafted file.
Which versions of SoX are affected by REDHAT-BUG-1545866?
SoX versions up to and including 14.4.2 are affected by REDHAT-BUG-1545866.
What are the implications of the REDHAT-BUG-1545866 vulnerability?
The implications of the REDHAT-BUG-1545866 vulnerability include potential denial-of-service attacks on systems processing malformed audio files.