|
SoX WAV File Buffer Overflow Vulnerability
The WAV header handling code in SoX is reported to contain a buffer overflow vulnerability. This issue is due to a failure of the application to validate string lengths when copying user-supplied data into finite buffers in process memory. The attacker must be able to present a malicious WAV file to an unsuspecting user. The user must employ the affected application to either listen to, or process the malicious file. Ultimately a malicious attacker may exploit this issue to execute arbitrary code on the affected computer with the privileges of the user who started the affected application. |
|
|
Privacy Statement |