Описание
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
A heap-based buffer overflow vulnerability exists in the inlsx_aiffstartwrite.environment of the Sound Exchange sox library. A specially-crafted file can lead to a float point exception. This flaw allows an attacker to provide a malicious file to trigger this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | sox | Out of support scope | ||
| Red Hat Enterprise Linux 7 | sox | Out of support scope | ||
| Red Hat Enterprise Linux AI (RHEL AI) | sox | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in ...
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
Уязвимость функции rate_init компонента rate.c аудиоредактора Sound eXchange, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.2 Medium
CVSS3