The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sox | Aug 22, 2024 | Jul 31, 2017 |
| Debian | — | Upgrade sox | Feb 25, 2019 | Jul 31, 2017 |
| Gentoo Linux | — | Upgrade media-sound/sox. | Oct 9, 2018 | Jul 31, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade sox | Feb 22, 2021 | Jul 31, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade sox | Apr 30, 2021 | Jul 31, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade sox | Feb 3, 2021 | Jul 31, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 30, 2017 |
| Suse | — | Upgrade soxUpgrade sox-develUpgrade libsox3 | Feb 21, 2018 | Jul 31, 2017 |
| Ubuntu | — | Upgrade sox | Nov 19, 2024 | Jul 31, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub