Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.891705
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-1705-1)
Summary:The remote host is missing an update for the Debian 'sox' package(s) announced via the DLA-1705-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'sox' package(s) announced via the DLA-1705-1 advisory.

Vulnerability Insight:
Multiple vulnerabilities have been discovered in SoX (Sound eXchange), a sound processing program:

CVE-2017-11332

The startread function (wav.c) is affected by a divide-by-zero vulnerability when processing WAV file with zero channel count. This flaw might be leveraged by remote attackers using a crafted WAV file to perform denial of service (application crash).

CVE-2017-11358

The read_samples function (hcom.c) is affected by an invalid memory read vulnerability when processing HCOM files with invalid dictionaries. This flaw might be leveraged by remote attackers using a crafted HCOM file to perform denial of service (application crash).

CVE-2017-11359

The wavwritehdr function (wav.c) is affected by a divide-by-zero vulnerability when processing WAV files with invalid channel count over 16 bits. This flaw might be leveraged by remote attackers using a crafted WAV file to perform denial of service (application crash).

CVE-2017-15371

The sox_append_comment() function (formats.c) is vulnerable to a reachable assertion when processing FLAC files with metadata declaring more comments than provided. This flaw might be leveraged by remote attackers using crafted FLAC data to perform denial of service (application crash).

For Debian 8 Jessie, these problems have been fixed in version 14.4.1-5+deb8u3.

We recommend that you upgrade your sox packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'sox' package(s) on Debian 8.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-11332
https://www.exploit-db.com/exploits/42398/
https://security.gentoo.org/glsa/201810-02
http://seclists.org/fulldisclosure/2017/Jul/81
https://lists.debian.org/debian-lts-announce/2017/11/msg00043.html
https://lists.debian.org/debian-lts-announce/2019/03/msg00007.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-11358
http://www.openwall.com/lists/oss-security/2023/02/03/3
http://www.openwall.com/lists/oss-security/2023/02/04/2
http://www.openwall.com/lists/oss-security/2023/02/05/1
http://www.openwall.com/lists/oss-security/2023/02/06/1
Common Vulnerability Exposure (CVE) ID: CVE-2017-11359
Common Vulnerability Exposure (CVE) ID: CVE-2017-15371
https://bugzilla.redhat.com/show_bug.cgi?id=1500570
CopyrightCopyright (C) 2019 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.