Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18189

Опубликовано: 15 фев. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

A NULL pointer dereference flaw found in the way SoX handled processing of AIFF files. An attacker could potentially use this flaw to crash the SoX application by tricking it into processing crafted AIFF files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5soxNot affected
Red Hat Enterprise Linux 6soxAffected
Red Hat Enterprise Linux 7soxFixedRHSA-2019:228306.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1545866sox: NULL pointer dereference in startread function in xa.c

EPSS

Процентиль: 91%
0.05055
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

CVSS3: 7.5
nvd
больше 8 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

CVSS3: 7.5
debian
больше 8 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4 ...

CVSS3: 7.5
github
около 4 лет назад

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

oracle-oval
почти 7 лет назад

ELSA-2019-2283: sox security update (LOW)

EPSS

Процентиль: 91%
0.05055
Низкий

3.3 Low

CVSS3