Description
A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3315-1 | sox security update |
Debian DSA |
DSA-5356-1 | sox security update |
EUVD |
EUVD-2021-26942 | A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information. |
Ubuntu USN |
USN-5904-1 | SoX vulnerabilities |
References
History
Fri, 27 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound Exchange Project
Sound Exchange Project sound Exchange |
|
| CPEs | cpe:2.3:a:sound_exchange_project:sound_exchange:14.4.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Sox Project
Sox Project sox |
Sound Exchange Project
Sound Exchange Project sound Exchange |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:08.189Z
Reserved: 2021-07-12T00:00:00.000Z
Link: CVE-2021-3643
No data.
Status : Modified
Published: 2022-05-02T19:15:08.290
Modified: 2025-06-27T18:51:27.923
Link: CVE-2021-3643
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN