Out-of-bounds read in SoX - CVE-2021-3643

 

Out-of-bounds read in SoX - CVE-2021-3643

Published: March 22, 2023


Vulnerability identifier: #VU73932
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3643
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the lsx_adpcm_init() function in libsox. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

SoX
Debian Linux
Ubuntu
libsox2 (Ubuntu package)
sox (Ubuntu package)
libsox3 (Ubuntu package)
sox (Debian package)

How to mitigate CVE-2021-3643

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libsox2 (Ubuntu package) - update to Ubuntu Pro
sox (Ubuntu package) - addressed in versions Ubuntu Pro, 14.4.2+git20190427-3ubuntu0.1, 14.4.2+git20190427-3ubuntu0.2, 14.4.2+git20190427-2+deb11u1build0.20.04.1, 14.4.2+git20190427-2+deb11u1build0.22.04.1, 14.4.2+git20190427-2+deb11u2build0.20.04.1, 14.4.2+git20190427-2+deb11u2build0.22.04.1, 14.4.2-3ubuntu0.18.04.2, 14.4.2-3ubuntu0.18.04.3
libsox3 (Ubuntu package) - addressed in versions 14.4.2+git20190427-3ubuntu0.1, 14.4.2+git20190427-3ubuntu0.2, 14.4.2+git20190427-2+deb11u1build0.20.04.1, 14.4.2+git20190427-2+deb11u1build0.22.04.1, 14.4.2+git20190427-2+deb11u2build0.20.04.1, 14.4.2+git20190427-2+deb11u2build0.22.04.1, 14.4.2-3ubuntu0.18.04.2, 14.4.2-3ubuntu0.18.04.3
sox (Debian package) - update to 14.4.2+git20190427-2+deb11u1

External References

Related Security Bulletins