435
VMScore

CVE-2017-11359

Published: 31/07/2017 Updated: 08/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote malicious users to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sound exchange project sound exchange 14.4.2

debian debian linux 7.0

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #870328 sox: CVE-2017-11332 CVE-2017-11358 CVE-2017-11359 Package: src:sox; Maintainer for src:sox is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 1 Aug 2017 05:21:01 UTC Severity: important Tags: securit ...
The wavwritehdr function in wavc in Sound eXchange (SoX) 1442 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file ...

Exploits

Sound eXchange (SoX) multiple vulnerabilities ================ Author : qflbwu =============== Introduction: ============= SoX is a cross-platform (Windows, Linux, MacOS X, etc) command line utility that can convert various formats of computer audio files in to other formats It can also apply various effects to these sound files, and, as an ad ...