There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-sox | Feb 25, 2019 | Oct 16, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-media-sound-sox | Oct 9, 2018 | Oct 16, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-sox | Feb 22, 2021 | Oct 16, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-sox | Apr 30, 2021 | Oct 16, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-sox | Feb 3, 2021 | Oct 16, 2017 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 11, 2017 |
| Suse | — | suse-upgrade-libsox3suse-upgrade-soxsuse-upgrade-sox-devel | Feb 21, 2018 | Oct 16, 2017 |
| Ubuntu | ubuntu-upgrade-sox | Nov 19, 2024 | Oct 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub