DSA-5356-1 sox -- security update

Related Vulnerabilities: CVE-2021-3643   CVE-2021-23159   CVE-2021-23172   CVE-2021-23210   CVE-2021-33844   CVE-2021-40426   CVE-2022-31650   CVE-2022-31651  

Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. For the stable distribution (bullseye), these problems have been fixed in version 14.4.2+git20190427-2+deb11u1. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sox

Debian Security Advisory

DSA-5356-1 sox -- security update

Date Reported:
20 Feb 2023
Affected Packages:
sox
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 1010374, Bug 1012138, Bug 1012516, Bug 1021133, Bug 1021134, Bug 1021135.
In Mitre's CVE dictionary: CVE-2021-3643, CVE-2021-23159, CVE-2021-23172, CVE-2021-23210, CVE-2021-33844, CVE-2021-40426, CVE-2022-31650, CVE-2022-31651.
More information:

Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

For the stable distribution (bullseye), these problems have been fixed in version 14.4.2+git20190427-2+deb11u1.

We recommend that you upgrade your sox packages.

For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sox