Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-32627

Опубликовано: 10 июл. 2023
Источник: debian
EPSS Низкий

Описание

A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
soxfixed14.4.2+git20190427-4package
soxno-dsabookwormpackage
soxno-dsabullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2212282

  • https://sourceforge.net/p/sox/bugs/369/

  • POC posted upstream is masked by fix of CVE-2021-3643, however sampling rate == 0,

  • thus FPE is not fixed by CVE-2021-3643

  • Proposed patch: https://sourceforge.net/p/sox/bugs/_discuss/thread/e759e37389/2ead/attachment/0026-CVE-2023-32627-Filter-null-sampling-rate-in-VOC-code.patch

EPSS

Процентиль: 15%
0.00049
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 2 лет назад

A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

CVSS3: 6.2
redhat
почти 3 года назад

A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

CVSS3: 6.2
nvd
больше 2 лет назад

A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

CVSS3: 6.2
github
больше 2 лет назад

A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

CVSS3: 6.2
fstec
больше 2 лет назад

Уязвимость функции read_samples() программы обработки звука Sound eXchange (SoX), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 15%
0.00049
Низкий