A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-sox | Aug 22, 2024 | May 2, 2022 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-soxamazon-linux-ami-2-upgrade-sox-debuginfoamazon-linux-ami-2-upgrade-sox-devel | Sep 8, 2023 | May 2, 2022 | |
| Debian | debian-upgrade-sox | Feb 13, 2023 | May 2, 2022 | |
| Suse | — | suse-upgrade-libsox3suse-upgrade-soxsuse-upgrade-sox-devel | Aug 9, 2024 | May 2, 2022 |
| Ubuntu | ubuntu-pro-upgrade-libsox2ubuntu-pro-upgrade-soxubuntu-upgrade-libsox3ubuntu-upgrade-sox | Mar 22, 2023 | May 2, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub