There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sox | Aug 22, 2024 | Oct 16, 2017 |
| Debian | — | Upgrade sox | Feb 25, 2019 | Oct 16, 2017 |
| Gentoo Linux | — | Upgrade media-sound/sox. | Oct 9, 2018 | Oct 16, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade sox | Feb 22, 2021 | Oct 16, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade sox | Apr 30, 2021 | Oct 16, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade sox | Feb 3, 2021 | Oct 16, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 11, 2017 |
| Suse | — | Upgrade libsox3Upgrade sox-develUpgrade sox | Feb 21, 2018 | Oct 16, 2017 |
| Ubuntu | — | Upgrade sox | Nov 19, 2024 | Oct 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub