In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
References
Configurations
History
No history.
Information
Published : 2018-02-15 10:29
Updated : 2023-11-07 02:41
NVD link : CVE-2017-18189
Mitre link : CVE-2017-18189
CVE.ORG link : CVE-2017-18189
JSON object : View
Products Affected
debian
- debian_linux
sound_exchange_project
- sound_exchange
CWE
CWE-476
NULL Pointer Dereference