Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11359

Опубликовано: 31 июл. 2017
Источник: debian

Описание

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
soxfixed14.4.2-2package
soxfixed14.4.1-5+deb9u2stretchpackage

Примечания

  • http://seclists.org/fulldisclosure/2017/Jul/81

  • Upstream bug report https://sourceforge.net/p/sox/bugs/296/

  • https://github.com/mansr/sox/commit/8b590b3a52f4ccc4eea3f41b4a067c38b3565b60

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

CVSS3: 3.3
redhat
больше 8 лет назад

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

CVSS3: 5.5
nvd
больше 8 лет назад

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

CVSS3: 5.5
github
больше 3 лет назад

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.