In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Link | Tags |
---|---|
https://sourceforge.net/p/sox/bugs/360/ | third party advisory exploit |
http://www.openwall.com/lists/oss-security/2023/02/03/3 | mailing list |
https://lists.debian.org/debian-lts-announce/2023/02/msg00009.html | mailing list |
https://www.debian.org/security/2023/dsa-5356 | vendor advisory |