CVE-2019-1010004
Summary
| CVE | CVE-2019-1010004 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-15 02:15:00 UTC |
| Updated | 2019-08-02 18:31:00 UTC |
| Description | SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sound Exchange Project | Sound Exchange | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SoX - Sound eXchange / Code / [dd8b63] /src/xa.c | MISC | sourceforge.net | Third Party Advisory |
| SoX - Sound eXchange / Bugs / #299 Invalid memory read via crafted .xa file | MISC | sourceforge.net | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.