CVE-2019-8355

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-8355
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-8355.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-8355
Related
Published
2019-02-15T23:29:00Z
Modified
2024-11-21T04:49:44Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsxvalloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow in channelsstart in remix.c.

References

Affected packages

Debian:11 / sox

Package

Name
sox
Purl
pkg:deb/debian/sox?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.4.2+git20190427-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / sox

Package

Name
sox
Purl
pkg:deb/debian/sox?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.4.2+git20190427-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / sox

Package

Name
sox
Purl
pkg:deb/debian/sox?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.4.2+git20190427-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}