CVE-2021-23159
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
25/08/2022
Last modified:
27/06/2025
Description
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sound_exchange_project:sound_exchange:14.4.2-7:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://access.redhat.com/security/cve/CVE-2021-23159
- https://bugzilla.redhat.com/show_bug.cgi?id=1975671
- https://security.archlinux.org/CVE-2021-23159
- https://sourceforge.net/p/sox/bugs/352/
- https://access.redhat.com/security/cve/CVE-2021-23159
- https://bugzilla.redhat.com/show_bug.cgi?id=1975671
- https://security.archlinux.org/CVE-2021-23159
- https://sourceforge.net/p/sox/bugs/352/



