Vulnerabilities > CVE-2017-15642 - Use After Free vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
sound-exchange-project
debian
CWE-416
nessus

Summary

In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-1695.NASL
    descriptionMultiple vulnerabilities have been discovered in SoX (Sound eXchange), a sound processing program : CVE-2017-15370 The ImaAdpcmReadBlock function (src/wav.c) is affected by a heap buffer overflow. This vulnerability might be leveraged by remote attackers using a crafted WAV file to cause denial of service (application crash). CVE-2017-15372 The lsx_ms_adpcm_block_expand_i function (adpcm.c) is affected by a stack based buffer overflow. This vulnerability might be leveraged by remote attackers using a crafted audio file to cause denial of service (application crash). CVE-2017-15642 The lsx_aiffstartread function (aiff.c) is affected by a use-after-free vulnerability. This flaw might be leveraged by remote attackers using a crafted AIFF file to cause denial of service (application crash). CVE-2017-18189 The startread function (xa.c) is affected by a NULL pointer dereference vulnerability. This flaw might be leveraged by remote attackers using a crafted Maxis XA audio file to cause denial of service (application crash). For Debian 8
    last seen2020-06-01
    modified2020-06-02
    plugin id122512
    published2019-03-01
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/122512
    titleDebian DLA-1695-1 : sox security update
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201810-02.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201810-02 (SoX: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in SoX. Please review the referenced CVE identifiers for details. Impact : A remote attacker, by enticing a user to process a crafted WAV, HCOM, SND, or AIFF file, could cause a Denial of Service condition. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id117967
    published2018-10-09
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/117967
    titleGLSA-201810-02 : SoX: Multiple vulnerabilities
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-1197.NASL
    descriptionVarious security vulnerabilities were discovered in sox, a command line utility to convert audio formats, that may lead to a denial of service (application crash / infinite loop) or memory corruptions by processing a malformed input file. For Debian 7
    last seen2020-03-17
    modified2017-12-01
    plugin id104939
    published2017-12-01
    reporterThis script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/104939
    titleDebian DLA-1197-1 : sox security update
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-AA1BF1711D.NASL
    description*SOX_PLUGINS* environment variable, added in *sox-14.4.2.0-16* to allow overriding standard *sox* path to plugins for the test purposes, is no longer exposed to user. ---- Security fix for **CVE-2017-15372**, **CVE-2017-15642**. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2018-02-21
    plugin id106913
    published2018-02-21
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/106913
    titleFedora 26 : sox (2018-aa1bf1711d)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-EC93095A73.NASL
    descriptionSecurity fix for **CVE-2017-15372**, **CVE-2017-15642**. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2018-02-15
    plugin id106830
    published2018-02-15
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/106830
    titleFedora 27 : sox (2018-ec93095a73)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2018-185.NASL
    descriptionThis update for sox fixes the following issues : - CVE-2017-11332: Fixed the startread function in wav.c, which allowed remote attackers to cause a DoS (divide-by-zero) via a crafted wav file. (boo#1081140) - CVE-2017-11358: Fixed the read_samples function in hcom.c, which allowed remote attackers to cause a DoS (invalid memory read) via a crafted hcom file. (boo#1081141) - CVE-2017-11359: Fixed the wavwritehdr function in wav.c, which allowed remote attackers to cause a DoS (divide-by-zero) when converting a a crafted snd file to a wav file. (boo#1081142) - CVE-2017-15370: Fixed a heap-based buffer overflow in the ImaExpandS function of ima_rw.c, which allowed remote attackers to cause a DoS during conversion of a crafted audio file. (boo#1063439) - CVE-2017-15371: Fixed an assertion abort in the function sox_append_comment() in formats.c, which allowed remote attackers to cause a DoS during conversion of a crafted audio file. (boo#1063450) - CVE-2017-15372: Fixed a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c, which allowed remote attackers to cause a DoS during conversion of a crafted audio file. (boo#1063456) - CVE-2017-15642: Fixed an Use-After-Free vulnerability in lsx_aiffstartread in aiff.c, which could be triggered by an attacker by providing a malformed AIFF file. (boo#1064576) - CVE-2017-18189: Fixed a NULL pointer dereference triggered by a corrupt header specifying zero channels in the startread function in xa.c, which allowed remote attackers to cause a DoS (boo#1081146).
    last seen2020-06-05
    modified2018-02-21
    plugin id106917
    published2018-02-21
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/106917
    titleopenSUSE Security Update : sox (openSUSE-2018-185)