A heap-based buffer overflow vulnerability exists in the...
High severity
Unreviewed
Published
Apr 15, 2022
to the GitHub Advisory Database
•
Updated Feb 23, 2023
Description
Published by the National Vulnerability Database
Apr 14, 2022
Published to the GitHub Advisory Database
Apr 15, 2022
Last updated
Feb 23, 2023
A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
References