A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sox | Aug 22, 2024 | May 2, 2022 |
| Amazon Linux Ami 2 | — | Upgrade sox-develUpgrade soxUpgrade sox-debuginfo | Sep 8, 2023 | May 2, 2022 |
| Debian | — | Upgrade sox | Feb 13, 2023 | May 2, 2022 |
| Suse | — | Upgrade sox-develUpgrade libsox3Upgrade sox | Aug 9, 2024 | May 2, 2022 |
| Ubuntu | — | Upgrade libsox2 (Ubuntu Pro)Upgrade soxUpgrade sox (Ubuntu Pro)Upgrade libsox3 | Mar 22, 2023 | May 2, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub