Описание
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
A heap-based buffer overflow vulnerability exists in a reachable assertion in the rate_init of the Sound Exchange sox library. A specially-crafted file can lead to a floating-point exception. This flaw allows an attacker to provide a malicious file to trigger this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | sox | Out of support scope | ||
| Red Hat Enterprise Linux 7 | sox | Out of support scope | ||
| Red Hat Enterprise Linux AI (RHEL AI) | sox | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwri ...
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
Уязвимость функции lsx_aiffstartwrite компонента aiff.c аудиоредактора Sound eXchange, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.2 Medium
CVSS3