CVE-2004-0557
sox - buffer overflows
EPSS 48.5%
Description
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
How to fix CVE-2004-0557
To remediate CVE-2004-0557, upgrade the affected package to a fixed version below.
- Debian/sox—upgrade to 12.17.4-9 or later
- Debian/sox—upgrade to 12.17.3-4woody2 or later
Is CVE-2004-0557 being exploited?
Moderate — EPSS is 48.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 12.17.4-9
- from 0, < 12.17.3-4woody2