Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-8356


An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow.


Published

2019-02-15T23:29:00.370

Last Modified

2024-11-21T04:49:44.950

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-129
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sound_exchange_project sound_exchange 14.4.2 Yes

References