VDB
GCVE-VVD-MAGEIA-2018-211
GCVE-VVD-MAGEIA-2018-211
Advisory Published
This update for sox fixes the following security issues:
* CVE-2017-11332: Fixed the startread function in wav.c, which allowed
remote attackers to cause a DoS (divide-by-zero) via a crafted wav file.
* CVE-2017-11358: Fixed the read_samples function in hcom.c, which
allowed remote attackers to cause a DoS (invalid memory read) via a
crafted hcom file.
* CVE-2017-11359: Fixed the wavwritehdr function in wav.c, which allowed
remote attackers to cause a DoS (divide-by-zero) when converting a a
crafted snd file to a wav file.
* CVE-2017-15372: Fixed a stack-based buffer overflow in the
lsx_ms_adpcm_block_expand_i function of adpcm.c, which allowed remote
attackers to cause a DoS during conversion of a crafted audio file.
* CVE-2017-15642: Fixed an Use-After-Free vulnerability in
lsx_aiffstartread in aiff.c, which could be triggered by an attacker by
providing a malformed AIFF file.
* CVE-2017-18189: In the startread function in xa.c in Sound eXchange
(SoX) through 14.4.2, a corrupt header specifying zero channels triggers
an infinite loop with a resultant NULL pointer dereference, which may
allow a remote attacker to cause a denial-of-service.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | sox | 0 (affected), 14.4.2-7.3.mga6 (unaffected) | — |
| Mageia | sox | 0 (affected), 14.4.1-6.3.mga5 (unaffected) | — |
Aliases
Transitive aliases
EUVD-2017-2988GHSA-vfg9-c8qr-pcrrVVD-MAGEIA-2018-105CNVD-2017-27183EUVD-2017-6826CVE-2017-15371EUVD-2017-6825EUVD-2017-6824CNVD-2017-27166EUVD-2017-2987EUVD-2017-2966GHSA-mh8q-537v-96gjGHSA-x8jm-gv8p-6967BDU:2023-01648GHSA-363g-vch7-x5j4GHSA-2454-3wfw-h893GHSA-mhq7-f3rw-g8h6GSD-2017-11359VVD-GENTOO-2017-627570GSD-2017-11358EUVD-2017-7093CNVD-2017-19459GSD-2017-11332GHSA-qcrg-ppmg-4fm2VVD-GENTOO-2017-634450CVE-2017-15370
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.