Hello,
I would like to report publicly new memory corruption vulnerabilities in the latest SoX, 14.4.2 - these have been reported in April 2015 through oCERT, but they have notified me they still haven't received a response from upstream.
Please see this shared folder, visible to anybody with the link:
The write heap buffer overflows are related to ADPCM handling in WAV files, while the read heap buffer overflow is while opening a .VOC.
For each crash, you have the input file and a .txt with the ASAN output.
Thanks,
Michele Spagnuolo
Google Security Team
This bug (reported as 201778 in FreeBSD) currently flags SoX as vulnerable and blocks make.
A (temporary) workaround is to build with -m DISABLE_VULNERABILITIES=yes.
The port maintiner reports that no upstream patch is available yet.