4.3
CVSSv2

CVE-2019-13590

Published: 14/07/2019 Updated: 10/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior check that it is a valid pointer, leading to a NULL pointer dereference on lsx_readbuf in formats_i.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sound exchange project sound exchange 14.4.2

Vendor Advisories

Debian Bug report logs - #932082 sox: CVE-2019-13590 Package: src:sox; Maintainer for src:sox is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 Jul 2019 20:21:16 UTC Severity: important Tags: security, upstream Found in version ...
Impact: Moderate Public Date: 2019-08-06 CWE: CWE-190 Bugzilla: 1737764: CVE-2019-13590 sox: integer ov ...