A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
The code performs a comparison such as an equality test between two float (floating point) values, but it uses comparison operators that do not account for the possibility of loss of precision.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2023-26590 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2212279 | third party advisory issue tracking |