REDHAT-BUG-1975666: Low severity sox (sound exchange) vulnerability
A vulnerability was found in SoX where, a heap overflow in hcom.c:161. Function startread with crafted hcomn file the vulnerability is exploitable.
References: https://sourceforge.net/p/sox/bugs/350/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1975666?
The severity of REDHAT-BUG-1975666 is considered to be high due to the potential for remote exploitation via crafted hcom files.
How do I fix REDHAT-BUG-1975666?
To fix REDHAT-BUG-1975666, users should update to the latest version of SoX that addresses the heap overflow vulnerability.
What causes the vulnerability identified in REDHAT-BUG-1975666?
The vulnerability in REDHAT-BUG-1975666 is caused by a heap overflow in the SoX program's hcom.c file during the startread function.
Who is affected by REDHAT-BUG-1975666?
Users of SoX (Sound eXchange) are affected by REDHAT-BUG-1975666, particularly those handling crafted hcom files.
What can attackers do with the REDHAT-BUG-1975666 vulnerability?
Attackers can exploit the REDHAT-BUG-1975666 vulnerability to execute arbitrary code on a system running a vulnerable version of SoX.