Bugzilla – Bug 1207046
VUL-1: CVE-2021-23159: sox: heap based overflow in formats_i.c
Last modified: 2023-01-11 12:15:05 UTC
rh#1975671 A vulnerability was found in SoX, where a heap based overflow was found in formats_i.c:376, function lsx_read_w_buf. References: https://sourceforge.net/p/sox/bugs/352/ References: https://bugzilla.redhat.com/show_bug.cgi?id=1975671 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-23159 https://www.cve.org/CVERecord?id=CVE-2021-23159 https://access.redhat.com/security/cve/CVE-2021-23159 https://sourceforge.net/p/sox/bugs/352/ https://security.archlinux.org/CVE-2021-23159
No upstream fix yet, I don't think this is an important bug tbh We ship it here: - openSUSE:Backports:SLE-15-SP3/sox 14.4.2 - openSUSE:Backports:SLE-15-SP4/sox 14.4.2 - openSUSE:Factory/sox 14.4.2