-Infinity
0

Vendor Risk Score

See how sox compares to other vendors in security performance

View Risk Score →
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Multiple buffer overflows in the stwavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

First published (updated )
Severity
7.5
Divide by Zero
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Rejected reason: This candidate is a duplicate of CVE-2017-11359.

First published (updated )
Severity
4

A vulnerabilty was found in sox v14.4.3, heap-buffer-overflow vulnerability that exists in the lsxreadbuf function at sox/src/formatsi.c:98:16. This vulnerability could lead to security issues such as denial of service, code execution, or information disclosure.

References: https://sourceforge.net/p/sox/bugs/367/

First published (updated )
Severity
4

A vulnerabilty was found in sox v14.4.3, heap-buffer-overflow vulnerability that exists in the startread function at sox/src/hcom.c:160:41. This vulnerability could lead to security issues such as denial of service, code execution, or information disclosure

References: https://sourceforge.net/p/sox/bugs/368/

First published (updated )
Severity
1
Null Pointer Dereference

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers a NULL pointer dereference, which may allow an attacker to cause denial-of-service via a specially crafted file.

External References:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121

Patch:

https://public-inbox.org/sox-devel/20171109114554.16297-1-mans@mansr.com/raw

First published (updated )
Severity
1

A vulnerabilty was found in sox v14.4.3, where floating point exception vulnerability that exists in the readsamples function at sox/src/voc.c:334:18. This vulnerability could lead to security issues such as denial of service.

References: https://sourceforge.net/p/sox/bugs/369/

First published (updated )
Severity
1

A vulnerability was found in SoX, where a heap based overflow was found in formatsi.c:376, function lsxreadwbuf.

References: https://sourceforge.net/p/sox/bugs/352/

First published (updated )
Severity
1
Divide by Zero

A vulnerability was found in SoX where, a divide by zero in voc.c:334, functon readsamples

References: https://sourceforge.net/p/sox/bugs/351/

First published (updated )
Severity
1

A vulnerability was found in SoX where, a heap overflow in hcom.c:161. Function startread with crafted hcomn file the vulnerability is exploitable.

References: https://sourceforge.net/p/sox/bugs/350/

First published (updated )
Severity
1

A vulnerability was found in SoX where a divide by zero bug in wav.c:967, functon startread. With crafted wav file, it crashes.

References: https://sourceforge.net/p/sox/bugs/349/

First published (updated )

I've tried the configure version and I get farther, but there is a problem in libdolbyb. I tried replacing configure.h with config.h but that didn't help. Yes, it should be ../src/soxconfig.h and there should be a symlink

included (opus support in sox seems to be cursed, has come and gone several Thanks for the compiler warnings too; I'm always having to stamp them out!

I'll write to the list again when 14.6.0.1 hits the racks addressing these.

M

M

A vulnerabilty was found in sox v14.4.3, Floating Point Exception vulnerability that exists in the lsxaiffstartwrite function at sox/src/aiff.c:622:58. This vulnerability could lead to security issues such as denial of service.

References: https://sourceforge.net/p/sox/bugs/370/.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203