Vulnerability Description
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sound Exchange Project | Sound Exchange | <= 14.4.2 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2019:2283
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121ExploitIssue TrackingMailing List
- https://lists.debian.org/debian-lts-announce/2019/02/msg00042.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://public-inbox.org/sox-devel/20171109114554.16297-1-mans%40mansr.com/raw
- https://access.redhat.com/errata/RHSA-2019:2283
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881121ExploitIssue TrackingMailing List
- https://lists.debian.org/debian-lts-announce/2019/02/msg00042.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://public-inbox.org/sox-devel/20171109114554.16297-1-mans%40mansr.com/raw
FAQ
What is CVE-2017-18189?
CVE-2017-18189 is a vulnerability with a CVSS score of 7.5 (HIGH). In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow...
How severe is CVE-2017-18189?
CVE-2017-18189 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18189?
Check the references section above for vendor advisories and patch information. Affected products include: Sound Exchange Project Sound Exchange, Debian Debian Linux.