A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 10
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sox | Aug 22, 2024 | Apr 14, 2022 |
| Debian | — | Upgrade sox | Feb 13, 2023 | Apr 14, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 14, 2022 |
| Suse | — | Upgrade sox-develUpgrade libsox3Upgrade sox | Aug 9, 2024 | Apr 14, 2022 |
| Ubuntu | — | Upgrade sox (Ubuntu Pro)Upgrade libsox2 (Ubuntu Pro)Upgrade soxUpgrade libsox3 | Mar 22, 2023 | Apr 14, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub