Menu

#350 Heap overflow in hcom.c

open
nobody
bug (6)
5
2025-03-02
2021-04-20
treebacker
No

There is a heap overflow in hcom.c:161. Function startread.
With crafted hcomn file, the vuln is exploitable.
Trigger command: ./src/.libs/sox bug2 -n noiseprof /dev/null

In AddressSanitizer:
c7yKUg.png

In gdb:
c7ylCj.png

The crafted file is attached.

1 Attachments

Discussion

  • Jan Starý

    Jan Starý - 2023-02-13
    $ sox ~/Downloads/sox-zero.hcom -n noiseprof /dev/null
    sox FAIL formats: can't open input file `/Users/hans/Downloads/sox-zero.hcom': premature EOF
    
     
  • Martin Guy

    Martin Guy - 2025-03-02

    This is CVE-2021-23172
    Absent in 14.4.2, Debian and sox_ng
    Present in 42b355 and sox.sf.net master

     

    Last edit: Martin Guy 2025-03-02

Log in to post a comment.