In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sox | Sox_project | 14.4.2 (including) | 14.4.2 (including) |
Sox | Ubuntu | bionic | * |
Sox | Ubuntu | esm-apps/xenial | * |
Sox | Ubuntu | focal | * |
Sox | Ubuntu | impish | * |
Sox | Ubuntu | jammy | * |
Sox | Ubuntu | kinetic | * |
Sox | Ubuntu | trusty/esm | * |
This Pillar covers several possibilities: