Sound Exchange · Sox · CVE-2019-1010004
Name of the Vulnerable Software and Affected Versions:
SoX - Sound eXchange versions 14.4.2 and earlier
Description:
The issue is related to an out-of-bounds read, which can cause a denial of service. It is located in the `read samples` function at `xa.c:219`. The attack vector involves a victim opening a specially crafted `.xa` file.
Recommendations:
For SoX - Sound eXchange versions 14.4.2 and earlier, consider avoiding the use of the `read samples` function until a fix is available. As a temporary workaround, restrict the opening of specially crafted `.xa` files to minimize the risk of exploitation.