An issue was discovered in SoX 14.4.2. lsx_make_lpf in...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jun 18, 2024
Description
Published by the National Vulnerability Database
Feb 15, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jun 18, 2024
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
References