Bug 1207043 - (CVE-2021-33844) VUL-1: CVE-2021-33844: sox divide by zero crash in wav.c
(CVE-2021-33844)
VUL-1: CVE-2021-33844: sox divide by zero crash in wav.c
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.5
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Pavol Rusnak
Security Team bot
https://smash.suse.de/issue/302852/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2023-01-11 11:23 UTC by Hu
Modified: 2023-01-11 12:15 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hu 2023-01-11 11:23:11 UTC
rh#1975664

A floating point exception (divide-by-zero) issue was discovered in SoX in
functon startread() of wav.c file. An attacker with a crafted wav file, could
cause an application to crash.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1975664
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-33844
https://www.cve.org/CVERecord?id=CVE-2021-33844
https://security.archlinux.org/CVE-2021-33844
https://access.redhat.com/security/cve/CVE-2021-33844
https://sourceforge.net/p/sox/bugs/349/