5
CVSSv2

CVE-2017-18189

Published: 15/02/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In the startread function in xa.c in Sound eXchange (SoX) up to and including 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote malicious user to cause a denial-of-service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sound exchange project sound exchange

debian debian linux 8.0

Vendor Advisories

Synopsis Low: sox security update Type/Severity Security Advisory: Low Topic An update for sox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed se ...
Debian Bug report logs - #881121 sox: CVE-2017-18189: null pointer dereference while running sox Package: sox; Maintainer for sox is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for sox is src:sox (PTS, buildd, popcon) Reported by: Joonun Jang <joonunjang@gmailcom> Date: Wed, 8 Nov 20 ...
A NULL pointer dereference flaw found in the way SoX handled processing of AIFF files An attacker could potentially use this flaw to crash the SoX application by tricking it into processing crafted AIFF files(CVE-2017-18189) ...
A NULL pointer dereference flaw found in the way SoX handled processing of AIFF files An attacker could potentially use this flaw to crash the SoX application by tricking it into processing crafted AIFF files ...
In the startread function in xac in Sound eXchange (SoX) through 1442, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service ...