Out-of-bounds read in SoX - CVE-2021-3643
Published: March 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the lsx_adpcm_init() function in libsox. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
Debian Linux
Ubuntu
libsox2 (Ubuntu package)
sox (Ubuntu package)
libsox3 (Ubuntu package)
sox (Debian package)
How to mitigate CVE-2021-3643
sox (Ubuntu package) - addressed in versions Ubuntu Pro, 14.4.2+git20190427-3ubuntu0.1, 14.4.2+git20190427-3ubuntu0.2, 14.4.2+git20190427-2+deb11u1build0.20.04.1, 14.4.2+git20190427-2+deb11u1build0.22.04.1, 14.4.2+git20190427-2+deb11u2build0.20.04.1, 14.4.2+git20190427-2+deb11u2build0.22.04.1, 14.4.2-3ubuntu0.18.04.2, 14.4.2-3ubuntu0.18.04.3
libsox3 (Ubuntu package) - addressed in versions 14.4.2+git20190427-3ubuntu0.1, 14.4.2+git20190427-3ubuntu0.2, 14.4.2+git20190427-2+deb11u1build0.20.04.1, 14.4.2+git20190427-2+deb11u1build0.22.04.1, 14.4.2+git20190427-2+deb11u2build0.20.04.1, 14.4.2+git20190427-2+deb11u2build0.22.04.1, 14.4.2-3ubuntu0.18.04.2, 14.4.2-3ubuntu0.18.04.3
sox (Debian package) - update to 14.4.2+git20190427-2+deb11u1