seclists.org
http://seclists.org/fulldisclosure/2017/Jul/81 CVE-2017-11332
MEDIUM
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
Record summary
CVE-2017-11332 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSound eXchange (SoX) 14.4.2 - Multiple VulnerabilitiesExploitDB exploitby qflb.wuNot analyzed1 file
References
6[debian-lts-announce] 20171130 [SECURITY] [DLA 1197-1] sox security updatemailing list
https://lists.debian.org/debian-lts-announce/2017/11/msg00043.html [debian-lts-announce] 20190305 [SECURITY] [DLA 1705-1] sox security updatemailing list
https://lists.debian.org/debian-lts-announce/2019/03/msg00007.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-11332 GLSA-201810-02Vendor advisory
https://security.gentoo.org/glsa/201810-02 42398exploit
https://www.exploit-db.com/exploits/42398