CVE-2019-8356

Description

An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.165

Associated Vulnerability

VulnerabilityOS Platform
Swiss army knife of sound processing (USN-4079-1) sox_14.4.1-5+deb8u4ubuntu0.1_i386.debLinux
Swiss army knife of sound processing (USN-4079-1) sox_14.4.1-5+deb8u4ubuntu0.1_amd64.debLinux
Swiss army knife of sound processing (USN-4079-1) libsox2_14.4.1-5+deb8u4ubuntu0.1_i386.debLinux
Swiss army knife of sound processing (USN-4079-1) libsox2_14.4.1-5+deb8u4ubuntu0.1_amd64.debLinux
Swiss army knife of sound processing (USN-4079-2) sox_14.4.2-3ubuntu0.18.04.1_i386.debLinux
Swiss army knife of sound processing (USN-4079-2) sox_14.4.2-3ubuntu0.18.04.1_amd64.debLinux
Swiss army knife of sound processing (USN-4079-2) sox_14.4.2-3ubuntu0.19.04.1_i386.debLinux
Swiss army knife of sound processing (USN-4079-2) sox_14.4.2-3ubuntu0.19.04.1_amd64.debLinux
Swiss army knife of sound processing (USN-4079-2) libsox3_14.4.2-3ubuntu0.18.04.1_i386.debLinux
Swiss army knife of sound processing (USN-4079-2) libsox3_14.4.2-3ubuntu0.18.04.1_amd64.debLinux
Swiss army knife of sound processing (USN-4079-2) libsox3_14.4.2-3ubuntu0.19.04.1_i386.debLinux
Swiss army knife of sound processing (USN-4079-2) libsox3_14.4.2-3ubuntu0.19.04.1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234