Out-of-bounds Write Affecting sox package, versions <14.4.2+git20190427-1
Threat Intelligence
EPSS
0.12% (47th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-SOX-337475
- published 16 Feb 2019
- disclosed 15 Feb 2019
How to fix?
Upgrade Debian:unstable sox to version 14.4.2+git20190427-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream sox package and not the sox package as distributed by Debian.
See How to fix? for Debian:unstable relevant fixed versions and status.
An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow.
References
- https://security-tracker.debian.org/tracker/CVE-2019-8356
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8356
- https://lists.debian.org/debian-lts-announce/2019/05/msg00040.html
- https://sourceforge.net/p/sox/bugs/321
- https://usn.ubuntu.com/4079-1/
- https://usn.ubuntu.com/4079-2/
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2019-8356