An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sox | Nov 8, 2019 | Feb 15, 2019 |
| Debian | — | Upgrade sox | May 29, 2019 | Feb 15, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 15, 2019 |
| Ubuntu | — | Upgrade libsox2Upgrade libsox3Upgrade sox | Jul 31, 2019 | Feb 15, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub