Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-5904-1

Ubuntu Security Notice 5904-1 - Helmut Grohne discovered that SoX incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. Helmut Grohne discovered that SoX incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service.

Packet Storm
#vulnerability#ubuntu#dos#git
==========================================================================Ubuntu Security Notice USN-5904-1March 02, 2023sox vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 22.10- Ubuntu 22.04 LTS- Ubuntu 20.04 LTS- Ubuntu 18.04 LTS- Ubuntu 16.04 ESM- Ubuntu 14.04 ESMSummary:Several security issues were fixed in SoX.Software Description:- sox: Swiss army knife of sound processingDetails:Helmut Grohne discovered that SoX incorrectly handled certain inputs. If auser or an automated system were tricked into opening a specially craftedinput file, a remote attacker could possibly use this issue to cause adenial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,and Ubuntu 18.04 LTS. (CVE-2019-13590)Helmut Grohne discovered that SoX incorrectly handled certain inputs. If auser or an automated system were tricked into opening a specially craftedinput file, a remote attacker could possibly use this issue to cause adenial of service. (CVE-2021-23159, CVE-2021-23172, CVE-2021-23210,CVE-2021-33844, CVE-2021-3643, CVE-2021-40426, CVE-2022-31650, andCVE-2022-31651)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 22.10:   libsox3                         14.4.2+git20190427-3ubuntu0.1   sox                             14.4.2+git20190427-3ubuntu0.1Ubuntu 22.04 LTS:   libsox3                          14.4.2+git20190427-2+deb11u1build0.22.04.1   sox                              14.4.2+git20190427-2+deb11u1build0.22.04.1Ubuntu 20.04 LTS:   libsox3                          14.4.2+git20190427-2+deb11u1build0.20.04.1   sox                              14.4.2+git20190427-2+deb11u1build0.20.04.1Ubuntu 18.04 LTS:   libsox3                         14.4.2-3ubuntu0.18.04.2   sox                             14.4.2-3ubuntu0.18.04.2Ubuntu 16.04 ESM:   libsox2                         14.4.1-5+deb8u4ubuntu0.1+esm1   sox                             14.4.1-5+deb8u4ubuntu0.1+esm1Ubuntu 14.04 ESM:   libsox2                         14.4.1-3ubuntu1.1+esm2   sox                             14.4.1-3ubuntu1.1+esm2In general, a standard system update will make all the necessary changes.References:https://ubuntu.com/security/notices/USN-5904-1 <https://ubuntu.com/security/notices/USN-5904-1>   CVE-2019-13590, CVE-2021-23159, CVE-2021-23172, CVE-2021-23210,   CVE-2021-33844, CVE-2021-3643, CVE-2021-40426, CVE-2022-31650,   CVE-2022-31651Package Information:https://launchpad.net/ubuntu/+source/sox/14.4.2+git20190427-3ubuntu0.1 <https://launchpad.net/ubuntu/+source/sox/14.4.2+git20190427-3ubuntu0.1>https://launchpad.net/ubuntu/+source/sox/14.4.2+git20190427-2+deb11u1build0.22.04.1 <https://launchpad.net/ubuntu/+source/sox/14.4.2+git20190427-2+deb11u1build0.22.04.1>https://launchpad.net/ubuntu/+source/sox/14.4.2+git20190427-2+deb11u1build0.20.04.1 <https://launchpad.net/ubuntu/+source/sox/14.4.2+git20190427-2+deb11u1build0.20.04.1>https://launchpad.net/ubuntu/+source/sox/14.4.2-3ubuntu0.18.04.2 <https://launchpad.net/ubuntu/+source/sox/14.4.2-3ubuntu0.18.04.2>

Related news

Ubuntu Security Notice USN-5904-2

Ubuntu Security Notice 5904-2 - USN-5904-1 fixed vulnerabilities in SoX. It was discovered that the fix for CVE-2021-33844 was incomplete. This update fixes the problem. Helmut Grohne discovered that SoX incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

Debian Security Advisory 5356-1

Debian Linux Security Advisory 5356-1 - Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed.

CVE-2021-33844: Invalid Bug ID

A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.

CVE-2021-23210: SoX - Sound eXchange / Bugs

A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.

CVE-2021-23172: Invalid Bug ID

A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.

CVE-2021-23159: Red Hat Customer Portal - Access to 24x7 support and knowledge

A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.

CVE-2022-31651: SoX - Sound eXchange / Bugs

In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.

CVE-2021-3643: Invalid Bug ID

A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.

CVE-2021-40426: TALOS-2021-1434 || Cisco Talos Intelligence Group

A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2019-13590: SoX - Sound eXchange / Bugs

An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior check that it is a valid pointer, leading to a NULL pointer dereference on lsx_readbuf in formats_i.c.

Packet Storm: Latest News

Zeek 6.0.8