Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian 10: DLA-3315-1 Critical: SoX Memory Access Threats

debian lts
Calendar Grey February 10, 2023
Dist Debian Esm H88
The latest update addresses significant vulnerabilities in SoX, improving protection against memory-related problems and ensuring proper validation of file formats.
This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions

Summary

CVE-2019-13590

In sox-fmt.h (startread function), there is an integer overflow on the
result of integer addition (wraparound to 0) fed into the lsx_calloc macro
that wraps malloc. When a NULL pointer is returned, it is used without a
prior check that it is a valid pointer, leading to a NULL pointer
dereference on lsx_readbuf in formats_i.c.

CVE-2021-3643

The lsx_adpcm_init function within libsox leads to a
global-buffer-overflow. This flaw allows an attacker to input a malicious
file, leading to the disclosure of sensitive information.

CVE-2021-23159

A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is
exploitable with a crafted file, that could cause an application to
crash.

CVE-2021-23172

A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: sox
Version: 14.4.2+git20190427-1+deb10u1
CVE ID: CVE-2019-13590 CVE-2021-3643 CVE-2021-23159 CVE-2021-23172
Debian Bug: 933372 1010374 1012138 1012516 1021133 1021134 1021135

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here