Fedora: 2,1: sox Buffer overflow vulnerabilities
Summary
SoX (Sound eXchange) is a sound file format converter SoX can convert
between many different digitized sound formats and perform simple
sound manipulation functions, including sound effects.
SoX (Sound eXchange) is a sound file format converter SoX can convert
between many different digitized sound formats and perform simple
sound manipulation functions, including sound effects.
Update Information:
Updated sox packages that fix buffer overflows in the WAV file handling
code are now available.
Buffer overflows existed in the parsing of WAV file header fields. It
was possible that a malicious WAV file could have caused arbitrary
code to be executed when the file was played or converted.
* Fri Jul 23 2004 Bill Nottingham <notting@redhat.com> 12.17.4-4.fc2
- add patch for buffer overflow in wav code (CAN-2004-0557, #128158)
* Fri Jul 09 2004 Bill Nottingham <notting@redhat.com> 12.17.4-4
- add patch for 64-bit problem (#127502)
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
This update can be downloaded from:
1020f447f7a723dab88d8bc17b364a7b SRPMS/sox-12.17.4-4.fc2.src.rpm 7ce0bf74c84febdd8013d61a06f3d46c x86_64/sox-12.17.4-4.fc2.x86_64.rpm cd8c74016bf280afceb513a20184af93 x86_64/sox-devel-12.17.4-4.fc2.x86_64.rpm d891be1475f207ce0103fdac5ef832f1 x86_64/debug/sox-debuginfo-12.17.4-4.fc2.x86_64.rpm a4e7728468e13aa426b7433d0bafb210 i386/sox-12.17....
Read the Full AdvisoryChange Log
References
CORE 2: Fedora Update Notification FEDORA-2004-244 2004-07-28 Product : Fedora Core 2 Name : sox Version : 12.17.4 Release : 4.fc2 Summary : A general purpose sound file conversion tool. Description : SoX (Sound eXchange) is a sound file format converter SoX can convert between many different digitized sound formats and perform simple sound manipulation functions, including sound effects.