Logo
vulnerabilityCVE-2019-13590
Name
CVE-2019-13590
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior check that it is a valid pointer, leading to a NULL pointer dereference on lsx_readbuf in formats_i.c.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
sox
Patched

Vulnerability Ratings#


5.5
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
7524160b29a476f7e87bc14fddf12d349f9a3c5e
Not Affected
buildroot
master
7524160b29a476f7e87bc14fddf12d349f9a3c5e
Not Affected
openwrt
master
14.5.1.1-r1
Not Affected
openwrt
openwrt-25.12
14.5.1.1-r1
Not Affected
yocto
master
14.4.2+git
Not Affected
yocto
scarthgap
14.4.2
Patched

Resolved with patches#


sox (yocto:kirkstone)

#
Title
Author
Resolve
1
sox-fmt: validate comments_bytes before use (CVE-2019-13590)
Mans Rullgard <mans@mansr.com>
CVE-2019-13590

sox (yocto:scarthgap)

#
Title
Author
Resolve
1
sox-fmt: validate comments_bytes before use (CVE-2019-13590)
Mans Rullgard <mans@mansr.com>
CVE-2019-13590