Uncaught Exception in SoX - CVE-2023-32627
Published: September 7, 2023
Vulnerability identifier: #VU80520
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32627
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a floating point exception within the read_samples() function at sox/src/voc.c. A remote attacker can trick the victim to open a specially crafted file and crash the application.
Affected software
SoX
Ubuntu
libsox3 (Ubuntu package)
sox (Ubuntu package)
libsox2 (Ubuntu package)
Ubuntu
libsox3 (Ubuntu package)
sox (Ubuntu package)
libsox2 (Ubuntu package)
How to mitigate CVE-2023-32627
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
libsox3 (Ubuntu package) - addressed in versions Ubuntu Pro, 14.4.2+git20190427-3.4ubuntu1.1, 14.4.2+git20190427-2+deb11u2ubuntu0.20.04.1, 14.4.2+git20190427-2+deb11u2ubuntu0.22.04.1
sox (Ubuntu package) - addressed in versions Ubuntu Pro, 14.4.2+git20190427-3.4ubuntu1.1, 14.4.2+git20190427-2+deb11u2ubuntu0.20.04.1, 14.4.2+git20190427-2+deb11u2ubuntu0.22.04.1
libsox2 (Ubuntu package) - update to Ubuntu Pro
sox (Ubuntu package) - addressed in versions Ubuntu Pro, 14.4.2+git20190427-3.4ubuntu1.1, 14.4.2+git20190427-2+deb11u2ubuntu0.20.04.1, 14.4.2+git20190427-2+deb11u2ubuntu0.22.04.1
libsox2 (Ubuntu package) - update to Ubuntu Pro