Bug 2212283 (CVE-2023-34318)

Summary: CVE-2023-34318 sox: heap-buffer-overflow in src/hcom.c
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jeder, jkucera, jwakely
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-06-05 12:56:20 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2212285, 2212284    
Bug Blocks: 2203208    
Attachments:
Description Flags
spam none

Description Dhananjay Arunesh 2023-06-05 07:58:34 UTC
A vulnerabilty was found in sox v14.4.3, heap-buffer-overflow vulnerability that exists in the startread function at sox/src/hcom.c:160:41. This vulnerability could lead to security issues such as denial of service, code execution, or information disclosure

References:
https://sourceforge.net/p/sox/bugs/368/

Comment 1 Dhananjay Arunesh 2023-06-05 07:58:59 UTC
Created sox tracking bugs for this issue:

Affects: epel-all [bug 2212285]
Affects: fedora-all [bug 2212284]

Comment 2 Bruce Horne 2024-01-18 07:58:07 UTC Comment hidden (spam)
Comment 3 Bob Smith 2024-02-01 08:57:38 UTC Comment hidden (spam)
Comment 4 continuetable 2024-04-19 02:44:33 UTC Comment hidden (spam)
Comment 5 continuetable 2024-04-19 02:46:54 UTC Comment hidden (spam)
Comment 6 Anuj 2024-06-10 20:44:43 UTC Comment hidden (spam)
Comment 7 Piveso 2024-07-06 15:02:36 UTC Comment hidden (spam)
Comment 8 carlseoservices 2024-07-12 18:13:40 UTC Comment hidden (spam)
Comment 9 Charles Chase 2024-08-23 03:10:03 UTC Comment hidden (spam)
Comment 10 LA Limo Rentals 2024-08-29 16:13:30 UTC Comment hidden (spam)
Comment 11 LA Limo Rentals 2024-08-29 16:13:56 UTC Comment hidden (spam)
Comment 12 LA Limo Rentals 2024-08-29 16:15:18 UTC Comment hidden (spam)
Comment 13 tim disuza 2024-09-19 09:26:44 UTC Comment hidden (spam)
Comment 14 DanMar 2024-09-26 10:50:04 UTC Comment hidden (spam)
Comment 16 Aliyan Khan 2024-10-02 12:47:33 UTC Comment hidden (spam)
Comment 17 Aliyan Khan 2024-10-02 12:48:01 UTC Comment hidden (spam)
Comment 18 verti 2024-10-03 15:05:23 UTC Comment hidden (spam)
Comment 19 verti 2024-10-03 15:11:21 UTC Comment hidden (spam)
Comment 20 Ahsan Khan 2024-10-04 11:27:14 UTC Comment hidden (spam)
Comment 21 Ahsan Khan 2024-10-04 11:27:44 UTC Comment hidden (spam)
Comment 22 Ahsan Khan 2024-10-04 11:28:04 UTC Comment hidden (spam)
Comment 23 Isabella 2024-10-04 11:53:09 UTC Comment hidden (spam)
Comment 24 Isabella 2024-10-04 11:58:25 UTC Comment hidden (spam)
Comment 25 Isabella 2024-10-04 12:01:21 UTC Comment hidden (spam)
Comment 26 Pinoy Flix 2024-10-05 19:59:08 UTC Comment hidden (spam)
Comment 27 Steve Johnson 2024-10-14 17:08:16 UTC Comment hidden (spam)
Comment 28 sprunkigame 2024-10-17 07:19:33 UTC Comment hidden (spam)
Comment 29 Boats N Beds 2024-10-19 06:05:29 UTC Comment hidden (spam)
Comment 30 Boats N Beds 2024-10-19 06:07:05 UTC Comment hidden (spam)
Comment 31 Tomas 2024-11-04 13:01:51 UTC Comment hidden (spam)
Comment 32 Pablo 2024-11-12 15:00:47 UTC Comment hidden (spam)
Comment 33 Allan 2024-11-14 17:53:52 UTC Comment hidden (spam)
Comment 34 optionbrock 2024-12-28 10:30:09 UTC Comment hidden (spam)
Comment 35 tom petty 2025-01-10 01:29:53 UTC Comment hidden (spam)
Comment 36 Monica 2025-01-17 15:01:04 UTC Comment hidden (spam)
Comment 37 Monica 2025-01-17 15:02:30 UTC Comment hidden (spam)
Comment 38 Monica 2025-01-17 15:02:47 UTC Comment hidden (spam)
Comment 39 Tom 2025-02-14 11:41:29 UTC Comment hidden (spam)
Comment 40 Tom 2025-02-14 11:42:27 UTC Comment hidden (spam)
Comment 41 Ella 2025-02-19 10:32:41 UTC Comment hidden (spam)
Comment 42 Ella 2025-02-19 10:39:24 UTC Comment hidden (spam)
Comment 43 Blorian 2025-02-19 15:22:33 UTC Comment hidden (spam)
Comment 44 madilin thomas 2025-03-04 00:32:52 UTC Comment hidden (spam)
Comment 45 Jordan Horton 2025-04-21 14:46:57 UTC Comment hidden (spam)