See how sox compares to other vendors in security performance
Multiple buffer overflows in the stwavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
Rejected reason: This candidate is a duplicate of CVE-2017-11359.
A vulnerabilty was found in sox v14.4.3, heap-buffer-overflow vulnerability that exists in the lsxreadbuf function at sox/src/formatsi.c:98:16. This vulnerability could lead to security issues such as denial of service, code execution, or information disclosure.
References: https://sourceforge.net/p/sox/bugs/367/
A vulnerabilty was found in sox v14.4.3, heap-buffer-overflow vulnerability that exists in the startread function at sox/src/hcom.c:160:41. This vulnerability could lead to security issues such as denial of service, code execution, or information disclosure
References: https://sourceforge.net/p/sox/bugs/368/
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers a NULL pointer dereference, which may allow an attacker to cause denial-of-service via a specially crafted file.
External References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121
Patch:
https://public-inbox.org/sox-devel/20171109114554.16297-1-mans@mansr.com/raw
A vulnerabilty was found in sox v14.4.3, where floating point exception vulnerability that exists in the readsamples function at sox/src/voc.c:334:18. This vulnerability could lead to security issues such as denial of service.
References: https://sourceforge.net/p/sox/bugs/369/
A vulnerability was found in SoX, where a heap based overflow was found in formatsi.c:376, function lsxreadwbuf.
References: https://sourceforge.net/p/sox/bugs/352/
A vulnerability was found in SoX where, a divide by zero in voc.c:334, functon readsamples
References: https://sourceforge.net/p/sox/bugs/351/
A vulnerability was found in SoX where, a heap overflow in hcom.c:161. Function startread with crafted hcomn file the vulnerability is exploitable.
References: https://sourceforge.net/p/sox/bugs/350/
A vulnerability was found in SoX where a divide by zero bug in wav.c:967, functon startread. With crafted wav file, it crashes.
References: https://sourceforge.net/p/sox/bugs/349/
I've tried the configure version and I get farther, but there is a problem in libdolbyb. I tried replacing configure.h with config.h but that didn't help. Yes, it should be ../src/soxconfig.h and there should be a symlink
included (opus support in sox seems to be cursed, has come and gone several Thanks for the compiler warnings too; I'm always having to stamp them out!
I'll write to the list again when 14.6.0.1 hits the racks addressing these.
M
M
A vulnerabilty was found in sox v14.4.3, Floating Point Exception vulnerability that exists in the lsxaiffstartwrite function at sox/src/aiff.c:622:58. This vulnerability could lead to security issues such as denial of service.
References: https://sourceforge.net/p/sox/bugs/370/.