A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-soxamazon-linux-ami-2-upgrade-sox-debuginfoamazon-linux-ami-2-upgrade-sox-devel | Sep 8, 2023 | Jul 10, 2023 | |
| Debian | debian-upgrade-sox | Jul 30, 2024 | Jul 10, 2023 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jul 10, 2023 |
| Suse | — | suse-upgrade-libsox3suse-upgrade-soxsuse-upgrade-sox-devel | Oct 27, 2023 | Jul 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub