Updated sox packages fix CVE-2014-8145
Publication date: 31 Dec 2014Modification date: 31 Dec 2014
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-8145
Description
Updated sox packages fix security vulnerability: The sox command line tool is affected by two heap-based buffer overflows, respectively located in functions start_read() and AdpcmReadBlock(). A specially crafted wav file can be used to trigger the vulnerabilities (CVE-2014-8145).
References
SRPMS
4/core
- sox-14.4.1-3.1.mga4