In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sox | Feb 25, 2019 | Oct 19, 2017 |
| Gentoo Linux | — | Upgrade media-sound/sox. | Oct 9, 2018 | Oct 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade sox | Feb 22, 2021 | Oct 19, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade sox | Apr 30, 2021 | Oct 19, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade sox | Feb 3, 2021 | Oct 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 17, 2017 |
| Suse | — | Upgrade libsox3Upgrade sox-develUpgrade sox | Feb 21, 2018 | Oct 19, 2017 |
| Ubuntu | — | Upgrade sox | Nov 19, 2024 | Oct 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub