REDHAT-BUG-1975671: Low severity sox (sound exchange) vulnerability
A vulnerability was found in SoX, where a heap based overflow was found in formatsi.c:376, function lsxreadwbuf.
References: https://sourceforge.net/p/sox/bugs/352/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1975671?
REDHAT-BUG-1975671 has been classified as a heap-based overflow vulnerability which can lead to potential code execution.
How do I fix REDHAT-BUG-1975671?
To fix REDHAT-BUG-1975671, update SoX to the latest available version that addresses the heap overflow vulnerability.
What versions of SoX are affected by REDHAT-BUG-1975671?
All versions of SoX prior to the fix that addresses the vulnerability in formats_i.c are potentially affected by REDHAT-BUG-1975671.
What component is vulnerable in REDHAT-BUG-1975671?
The vulnerability in REDHAT-BUG-1975671 is found in the lsx_read_w_buf function located in formats_i.c.
Is REDHAT-BUG-1975671 exploitable by remote attackers?
Yes, REDHAT-BUG-1975671 may be exploited by remote attackers if they can send crafted input files to the SoX application.