Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 26 Security Advisory: Sox Software Critical Fixes for Threats

fedora
Calendar Grey February 20, 2018
Dist Fedora Esm H88
Fedora 26 releases an important security patch addressing two significant vulnerabilities, aimed at improving overall system reliability and operation.
*SOX_PLUGINS* environment variable, added in *sox-14.4.2.0-16* to allow overriding standard *sox* path to plugins for the test purposes, is no longer exposed to user

Summary

SoX (Sound eXchange) is a sound file format converter. SoX can convert

between many different digitized sound formats and perform simple

sound manipulation functions, including sound effects.

*SOX_PLUGINS* environment variable, added in *sox-14.4.2.0-16* to allow

overriding standard *sox* path to plugins for the test purposes, is no longer

exposed to user. ---- Security fix for **CVE-2017-15372**, **CVE-2017-15642**.

[ 1 ] Bug #1510923 - CVE-2017-15642 sox: Use-after-free in lsx_aiffstartread

https://bugzilla.redhat.com/show_bug.cgi?id=1510923

[ 2 ] Bug #1510919 - CVE-2017-15372 sox: Stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function

https://bugzilla.redhat.com/show_bug.cgi?id=1510919

su -c 'dnf upgrade sox' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 14.4.2.0
Release: 17.fc26
Summary: A general purpose sound file conversion tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here