PT-2019-11431 · Sound Exchange · Sox

Xct

·

Published

2019-02-28

·

Updated

2019-08-02

·

CVE-2019-1010004

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: SoX - Sound eXchange versions 14.4.2 and earlier
Description: The issue is related to an out-of-bounds read, which can cause a denial of service. It is located in the read samples function at xa.c:219. The attack vector involves a victim opening a specially crafted .xa file.
Recommendations: For SoX - Sound eXchange versions 14.4.2 and earlier, consider avoiding the use of the read samples function until a fix is available. As a temporary workaround, restrict the opening of specially crafted .xa files to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43855
AZL-45171
CVE-2019-1010004
DLA-1197-1
DLA-1695-1

Affected Products

Sox