Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39168
HistoryFeb 08, 2023 - 2:59 p.m.

Heap-based Buffer Overflow

2023-02-0814:59:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
vulnerability
software
start_read function
sphere.c
heap-based buffer overflow
attacker
specially-crafted file
trigger

EPSS

0.003

Percentile

70.4%

sox is vulnerable to heap-based buffer overflow. The vulnerability exists in the start_read() function in sphere.c because an attacker can use a specially-crafted file which can trigger this vulnerability.