FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0557

This CVE name corresponds to:

Entered Topic
2004-08-26 SoX buffer overflows when handling .WAV files

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0557
Phase Assigned(20040614)

Description

Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

References

Source Reference
FULLDISC 20040728 SoX buffer overflows when handling .WAV files
VULNWATCH 20040728 SoX buffer overflows when handling .WAV files
CONECTIVA CLA-2004:855
DEBIAN DSA-565
FEDORA FEDORA-2004-244
FEDORA FEDORA-2004-235
FEDORA FLSA:1945
GENTOO GLSA-200407-23
MANDRAKE MDKSA-2004:076
REDHAT RHSA-2004:409
BID 10819
OVAL oval:org.mitre.oval:def:9801
SECUNIA 12175
XF sox-wav-bo(16827)