Lucene search

K
nvd[email protected]NVD:CVE-2021-23172
HistoryAug 25, 2022 - 8:15 p.m.

CVE-2021-23172

2022-08-2520:15:08
CWE-120
CWE-787
web.nvd.nist.gov
6
sox
heap-buffer-overflow
startread
hcom.c
vulnerability
exploitable
crafted file
application crash

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.5%

A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.

Affected configurations

NVD
Node
sox_projectsoxMatch14.4.2-7

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.5%