Description
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1808-1 | sox security update |
EUVD |
EUVD-2019-17744 | An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow. |
Ubuntu USN |
USN-4079-1 | SoX vulnerabilities |
Ubuntu USN |
USN-4079-2 | SoX vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T21:17:30.508Z
Reserved: 2019-02-15T00:00:00.000Z
Link: CVE-2019-8354
No data.
Status : Modified
Published: 2019-02-15T23:29:00.277
Modified: 2024-11-21T04:49:44.647
Link: CVE-2019-8354
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN