CVE-2019-1010004

Related Vulnerabilities: CVE-2019-1010004  

Impact: Low Public Date: 2019-07-14 CWE: CWE-125->CWE-400 Bugzilla: 1730577: CVE-2019-1010004 sox: OOB read in function read_samples in xa.c:219 causing denial of service SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.

The MITRE CVE dictionary describes this issue as:

SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.

Find out more about CVE-2019-1010004 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 3.3
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 sox Under investigation
Red Hat Enterprise Linux 6 sox Under investigation
Red Hat Enterprise Linux 5 sox Under investigation