MGASA-2018-0105
Dashboard / Vulnerabilities / MGASA-2018-0105
MGASA-2018-0105
Summary: Updated sox packages fix security vulnerability
Details: There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file (CVE-2017-15370). There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file (CVE-2017-15371).
References: https://advisories.mageia.org/MGASA-2018-0105.html, https://bugs.mageia.org/show_bug.cgi?id=22469, https://lists.fedoraproject.org/archives/list/[email protected]/thread/LU6OQGTJOLIFAOPHQI6CPLGMN4KKMLIX/
Affected packages
Package
Name: sox
Purl: pkg:rpm/mageia/sox?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
