Debian Security Advisory

DLA-128-1 sox -- LTS security update

Date Reported:
03 Jan 2015
Affected Packages:
sox
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 773720.
In Mitre's CVE dictionary: CVE-2014-8145.
More information:

Michele Spagnuolo of the Google Security Team dicovered two heap-based buffer overflows in SoX, the Swiss Army knife of sound processing programs. A specially crafted wav file could cause an application using SoX to crash or, possibly, execute arbitrary code.

For Debian 6 Squeeze, these issues have been fixed in sox version 14.3.1-1+deb6u1