Menu

#351 div zero in voc.c

open
nobody
bug (6)
5
2025-03-02
2021-04-20
treebacker
No

There is a div zero in voc.c:334, functon read_samples.
Which crashes.
The trigger command: ./src/.libs/sox bug3 -n noiseprof /dev/null
In AddressSanitizer:
c7ymb8.png

In gdb:
c7yuVS.png

The crafted file is attached.

1 Attachments

Discussion

  • Jan Starý

    Jan Starý - 2023-02-13
    $ sox ~/Downloads/sox-zero.voc -n noiseprof /dev/null
    sox FAIL sox: `/Users/hans/Downloads/sox-zero.voc' format changed: Unsupported data format
    
     
  • Martin Guy

    Martin Guy - 2025-03-02

    This is CVE-2021-3643
    Absent in 14.4.2, Debian and sox_ng
    Present in 42b355 and sox.sf.net master

     

Log in to post a comment.

MongoDB Logo MongoDB