Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for sox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0329-1 Rating: important References: #1212060 #1212061 #1212062 #1212063 Cross-References: CVE-2019-13590 CVE-2021-23159 CVE-2021-33844 CVE-2021-3643 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 CVE-2023-32627 CVE-2023-34318 CVE-2023-34432 CVSS scores: CVE-2019-13590 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-33844 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-33844 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-3643 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2021-3643 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-40426 (NVD) : 10 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVE-2022-31650 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-31651 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2023-32627 (NVD) : 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2023-34318 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-34432 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for sox fixes the following issues: -Apply various fix patches taken from Debian package; it fixes also other entries (CVE-2022-31650 boo#1212060 CVE-2023-34318 boo#1212062 CVE-2023-34432 boo#1212063) - Fix floating point exception in src/voc.c (CVE-2023-32627 boo#1212061) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-329=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): libsox3-14.4.2-bp155.3.3.1 sox-14.4.2-bp155.3.3.1 sox-devel-14.4.2-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-13590.html https://www.suse.com/security/cve/CVE-2021-23159.html https://www.suse.com/security/cve/CVE-2021-33844.html https://www.suse.com/security/cve/CVE-2021-3643.html https://www.suse.com/security/cve/CVE-2021-40426.html https://www.suse.com/security/cve/CVE-2022-31650.html https://www.suse.com/security/cve/CVE-2022-31651.html https://www.suse.com/security/cve/CVE-2023-32627.html https://www.suse.com/security/cve/CVE-2023-34318.html https://www.suse.com/security/cve/CVE-2023-34432.html https://bugzilla.suse.com/1212060 https://bugzilla.suse.com/1212061 https://bugzilla.suse.com/1212062 https://bugzilla.suse.com/1212063 . This Fedora upgrade tackles critical vulnerabilities in git to ensure user privacy is maintained securely.. openSUSE Security, sox Update, Important Patch, Security Fixes, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for sox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0328-1 Rating: important References: #1212060 #1212061 #1212062 #1212063 Cross-References: CVE-2019-13590 CVE-2021-23159 CVE-2021-33844 CVE-2021-3643 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 CVE-2023-32627 CVE-2023-34318 CVE-2023-34432 CVSS scores: CVE-2019-13590 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-33844 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-33844 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-3643 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2021-3643 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-40426 (NVD) : 10 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVE-2022-31650 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-31651 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2023-32627 (NVD) : 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2023-34318 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-34432 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for sox fixes the following issues: -Apply various fix patches taken from Debian package; it fixes also other entries (CVE-2022-31650 boo#1212060 CVE-2023-34318 boo#1212062 CVE-2023-34432 boo#1212063) - Fix floating point exception in src/voc.c (CVE-2023-32627 boo#1212061) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-328=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libsox3-14.4.2-bp154.2.3.1 sox-14.4.2-bp154.2.3.1 sox-devel-14.4.2-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-13590.html https://www.suse.com/security/cve/CVE-2021-23159.html https://www.suse.com/security/cve/CVE-2021-33844.html https://www.suse.com/security/cve/CVE-2021-3643.html https://www.suse.com/security/cve/CVE-2021-40426.html https://www.suse.com/security/cve/CVE-2022-31650.html https://www.suse.com/security/cve/CVE-2022-31651.html https://www.suse.com/security/cve/CVE-2023-32627.html https://www.suse.com/security/cve/CVE-2023-34318.html https://www.suse.com/security/cve/CVE-2023-34432.html https://bugzilla.suse.com/1212060 https://bugzilla.suse.com/1212061 https://bugzilla.suse.com/1212062 https://bugzilla.suse.com/1212063 . This Fedora update addresses 12 vulnerabilities in curl, boosting security and stability.. openSUSE Security Update, sox repair, software update. . Severity: Important. LinuxSecurity.com Team
SoX is a command line utility that can convert various formats of computer audio files in to other formats. It can also apply various effects to these sound files during the conversion. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3527-1
One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3315-2
One of the security fixes released as DSA 5356 introduced a regression in the processing of specific WAV files. Updated sox packages are available to correct this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5356-2
CVE-2019-13590: sox-fmt validation CVE-2021-3643 and CVE-2021-23210: voc validation CVE-2021-23159 and CVE-2021-23172: hcom validation CVE-2021-33844: wav validation CVE-2021-40426: sphere validation . MGASA-2023-0059 - Updated sox packages fix security vulnerability Publication date: 27 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0059.html Type: security Affected Mageia releases: 8 CVE: CVE-2019-13590, CVE-2021-23159, CVE-2021-23172, CVE-2021-23210, CVE-2021-33844, CVE-2021-3643, CVE-2021-40426, CVE-2022-3165, CVE-2022-31650 CVE-2019-13590: sox-fmt validation CVE-2021-3643 and CVE-2021-23210: voc validation CVE-2021-23159 and CVE-2021-23172: hcom validation CVE-2021-33844: wav validation CVE-2021-40426: sphere validation CVE-2022-31650: aiff validation CVE-2022-31651: reject implausible rate References: - https://bugs.mageia.org/show_bug.cgi?id=30291 - https://talosintelligence.com/vulnerability_reports/TALOS-2021-1434 - https://lists.debian.org/debian-lts-announce/2023/02/msg00009.html - https://www.cve.org/CVERecord?id=CVE-2019-13590 - https://www.cve.org/CVERecord?id=CVE-2021-23159 - https://www.cve.org/CVERecord?id=CVE-2021-23172 - https://www.cve.org/CVERecord?id=CVE-2021-23210 - https://www.cve.org/CVERecord?id=CVE-2021-33844 - https://www.cve.org/CVERecord?id=CVE-2021-3643 - https://www.cve.org/CVERecord?id=CVE-2021-40426 - https://www.cve.org/CVERecord?id=CVE-2022-3165 - https://www.cve.org/CVERecord?id=CVE-2022-31650 SRPMS: - 8/core/sox-14.4.3-0.git20200117.3.1.mga8 . Recent updates to sox packages address various validation vulnerabilities in Mageia editions, thereby enhancing overall system security.. Sox Security,Mageia Software Update,Validate Flaws. . LinuxSecurity.com Team
Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5356-1
This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions. It also fixes a regression in hcom parsing introduced when fixing CVE-2017-11358. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3315-1
Get the latest Linux and open source security news straight to your inbox.