5.5
CVSSv3

CVE-2021-23172

Published: 25/08/2022 Updated: 12/02/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sox project sox 14.4.2-7

Vendor Advisories

Debian Bug report logs - #1021134 sox: CVE-2021-23172 Package: src:sox; Maintainer for src:sox is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 2 Oct 2022 18:03:04 UTC Severity: important Tags: security, upstream Found in version sox/ ...
Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed For the stable distribution (bullseye), these problems have been fixed in version 1442+git20190427-2+deb11u1 We recommen ...
One of the security fixes released as DSA 5356 introduced a regression in the processing of specific WAV files Updated sox packages are available to correct this issue For the stable distribution (bullseye), these problems have been fixed in version 1442+git20190427-2+deb11u2 We recommend that you upgrade your sox packages For the detailed se ...
A vulnerability was found in SoX, where a heap overflow was found in hcomc:161, function startread The vulnerability is exploitable with a crafted hcomn file ...