Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200407-23 ] SoX: Multiple buffer overflows
Date: Fri, 30 Jul 2004 15:01:20
Message-Id: 410A6257.5030803@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200407-23
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: SoX: Multiple buffer overflows
12 Date: July 30, 2004
13 Bugs: #58733
14 ID: 200407-23
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 SoX contains two buffer overflow vulnerabilities in the WAV header
22 parser code.
23
24 Background
25 ==========
26
27 SoX is a command line utility that can convert various formats of
28 computer audio files in to other formats.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 media-sound/sox <= 12.17.4-r1 >= 12.17.4-r2
37
38 Description
39 ===========
40
41 Ulf Harnhammar discovered two buffer overflows in the sox and play
42 commands when handling WAV files with specially crafted header fields.
43
44 Impact
45 ======
46
47 By enticing a user to play or convert a specially crafted WAV file an
48 attacker could execute arbitrary code with the permissions of the user
49 running SoX.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time. All users are encouraged to
55 upgrade to the latest available version of SoX.
56
57 Resolution
58 ==========
59
60 All SoX users should upgrade to the latest version:
61
62 # emerge sync
63
64 # emerge -pv ">=media-sound/sox-12.17.4-r2"
65 # emerge ">=media-sound/sox-12.17.4-r2"
66
67 References
68 ==========
69
70 [ 1 ] Full Disclosure Announcement
71
72 http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1141.html
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-200407-23.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 http://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2004 Gentoo Foundation, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/1.0
101
102 -----BEGIN PGP SIGNATURE-----
103 Version: GnuPG v1.2.4 (GNU/Linux)
104 Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
105
106 iD8DBQFBCmJWvcL1obalX08RAijlAJ9C3qaGE3pW9JKve99S0qABwiTbuQCeKcn6
107 NdGB0d0mJHQx2OOZtYNdFEw=
108 =nuUa
109 -----END PGP SIGNATURE-----