Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SoX WAV File Buffer Overflow Vulnerability

The WAV header handling code in SoX is reported to contain a buffer overflow vulnerability. This issue is due to a failure of the application to validate string lengths when copying user-supplied data into finite buffers in process memory.

The attacker must be able to present a malicious WAV file to an unsuspecting user. The user must employ the affected application to either listen to, or process the malicious file.

Ultimately a malicious attacker may exploit this issue to execute arbitrary code on the affected computer with the privileges of the user who started the affected application.







 

Privacy Statement
Copyright 2008, SecurityFocus