CVE-2014-8145
Summary
| CVE | CVE-2014-8145 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-31 22:59:00 UTC |
| Updated | 2019-03-01 23:17:00 UTC |
| Description | Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Oracle Bulletin Board Update - January 2015 |
CONFIRM |
www.oracle.com |
Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2015:015 | Mandriva |
MANDRIVA |
www.mandriva.com |
Broken Link |
| [SECURITY] [DLA 1687-1] sox security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-3112-1 sox |
DEBIAN |
www.debian.org |
Third Party Advisory |
| SoX 14.4.1 Heap Buffer Overflow ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Exploit, Third Party Advisory, VDB Entry |
| oCERT.org - oCERT Advisories |
MISC |
www.ocert.org |
Third Party Advisory, US Government Resource |
| SoX 'wav' File Multiple Heap Buffer Overflow Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| SoX: User-assisted execution of arbitrary code (GLSA 201612-30) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Mageia Advisory: MGASA-2014-0561 - Updated sox packages fix CVE-2014-8145 |
CONFIRM |
advisories.mageia.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690324 Free Berkeley Software Distribution (FreeBSD) Security Update for sox (92cda470-30cb-11e5-a4a5-002590263bf5)