Bugzilla – Bug 1200056
VUL-0: CVE-2021-40426: sox: heap-based buffer overflow vulnerability exists in the sphere.c start_read() function
Last modified: 2022-05-31 09:15:01 UTC
rh#2091798 A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. https://talosintelligence.com/vulnerability_reports/TALOS-2021-1434 References: https://bugzilla.redhat.com/show_bug.cgi?id=2091798 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-40426 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40426 http://www.cvedetails.com/cve/CVE-2021-40426/ https://talosintelligence.com/vulnerability_reports/TALOS-2021-1434
Affected: - openSUSE:Backports:SLE-15-SP3/sox 14.4.2 - openSUSE:Backports:SLE-15-SP4/sox 14.4.2 - openSUSE:Factory/sox 14.4.2