Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18189

Опубликовано: 15 фев. 2018
Источник: redhat
CVSS3: 3.3

Описание

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

A NULL pointer dereference flaw found in the way SoX handled processing of AIFF files. An attacker could potentially use this flaw to crash the SoX application by tricking it into processing crafted AIFF files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5soxNot affected
Red Hat Enterprise Linux 6soxAffected
Red Hat Enterprise Linux 7soxFixedRHSA-2019:228306.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1545866sox: NULL pointer dereference in startread function in xa.c

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

CVSS3: 7.5
nvd
почти 8 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

CVSS3: 7.5
debian
почти 8 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4 ...

CVSS3: 7.5
github
больше 3 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

oracle-oval
больше 6 лет назад

ELSA-2019-2283: sox security update (LOW)

3.3 Low

CVSS3