seclists.org
http://seclists.org/fulldisclosure/2017/Jul/81 CVE-2017-11358
MEDIUM
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
Record summary
CVE-2017-11358 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSound eXchange (SoX) 14.4.2 - Multiple VulnerabilitiesExploitDB exploitby qflb.wuNot analyzed1 file
References
10[oss-security] 20230203 sox: patches for old vulnerabilitiesmailing list
http://www.openwall.com/lists/oss-security/2023/02/03/3 [oss-security] 20230204 Re: sox: patches for old vulnerabilitiesmailing list
http://www.openwall.com/lists/oss-security/2023/02/04/2 [oss-security] 20230205 Re: sox: patches for old vulnerabilitiesmailing list
http://www.openwall.com/lists/oss-security/2023/02/05/1 [oss-security] 20230206 Re: sox: patches for old vulnerabilitiesmailing list
http://www.openwall.com/lists/oss-security/2023/02/06/1 [debian-lts-announce] 20171130 [SECURITY] [DLA 1197-1] sox security updatemailing list
https://lists.debian.org/debian-lts-announce/2017/11/msg00043.html [debian-lts-announce] 20190305 [SECURITY] [DLA 1705-1] sox security updatemailing list
https://lists.debian.org/debian-lts-announce/2019/03/msg00007.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-11358 GLSA-201810-02Vendor advisory
https://security.gentoo.org/glsa/201810-02 42398exploit
https://www.exploit-db.com/exploits/42398