RHEL 3 : sox (RHSA-2004:409)

Critical Nessus Plugin ID 13853


The remote Red Hat host is missing one or more security updates.


Updated sox packages that fix buffer overflows in the WAV file handling code are now available.

SoX (Sound eXchange) is a sound file format converter. SoX can convert between many different digitized sound formats and perform simple sound manipulation functions, including sound effects.

Buffer overflows existed in the parsing of WAV file header fields. It was possible that a malicious WAV file could have caused arbitrary code to be executed when the file was played or converted. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0557 to these issues.

All users of sox should upgrade to these updated packages, which resolve these issues as well as fix a number of minor bugs.


Update the affected sox and / or sox-devel packages.

See Also



Plugin Details

Severity: Critical

ID: 13853

File Name: redhat-RHSA-2004-409.nasl

Version: $Revision: 1.20 $

Type: local

Agent: unix

Published: 2004/07/30

Modified: 2016/12/28

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:sox, p-cpe:/a:redhat:enterprise_linux:sox-devel, cpe:/o:redhat:enterprise_linux:3

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 2004/07/29

Vulnerability Publication Date: 2004/07/29

Reference Information

CVE: CVE-2004-0557

OSVDB: 8267

RHSA: 2004:409