First published: Thu Jun 24 2021(Updated: )
A vulnerability was found in SoX where, a heap overflow in hcom.c:161. Function startread with crafted hcomn file the vulnerability is exploitable. References: <a href="https://sourceforge.net/p/sox/bugs/350/">https://sourceforge.net/p/sox/bugs/350/</a>
Affected Software | Affected Version | How to fix |
---|---|---|
SoX (Sound eXchange) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1975666 is considered to be high due to the potential for remote exploitation via crafted hcom files.
To fix REDHAT-BUG-1975666, users should update to the latest version of SoX that addresses the heap overflow vulnerability.
The vulnerability in REDHAT-BUG-1975666 is caused by a heap overflow in the SoX program's hcom.c file during the startread function.
Users of SoX (Sound eXchange) are affected by REDHAT-BUG-1975666, particularly those handling crafted hcom files.
Attackers can exploit the REDHAT-BUG-1975666 vulnerability to execute arbitrary code on a system running a vulnerable version of SoX.