sox: OOB read in function read_samples in xa.c:219 causing denial of service
Published Jul 15, 2019
5.5
MEDIUMCVSS 3.0
EPSS 1.26%
Description
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
Affected products
-
- Version ≤ 14.4.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SourceForge | SoX - Sound eXchange | n/a |
|
- ≤ 14.4.2
No data.
Red Hat Enterprise Linux 5
sox
Out of support scope
Red Hat Enterprise Linux 6
sox
Out of support scope
Red Hat Enterprise Linux 7
sox
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | sox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | sox | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | sox | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is only a security vulnerability for applications linking against libsox, that may be caused to crash prematurely or even, under special circumstances, disclose sensitive memory contents. Attacks against the sox binaries do not constitute a security threat since these are all short-run programs that do not hold sensitive data in memory.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.26% (0.01263) | 68.62th | v5 (v2026.06.15) |
| Aug 23, 2026 | 2.09% (0.02094) | 79.97th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.06% (0.00063) | 27.99th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.06% (0.00063) | 27.51th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00063) | 25.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.40% (0.01404) | 49.02th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.40% (0.03396) | 67.40th | v1 |
| Jan 6, 2022 | 3.40% (0.03396) | 67.08th | v1 |
| Jan 5, 2022 | 0.78% (0.00777) | 52.24th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.78% (0.00777) | 0.00th | v1 |
References (6)
- https://access.redhat.com/security/cve/CVE-2019-1010004 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1730577 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-1010004
- https://sourceforge.net/p/sox/bugs/299/ x_refsource_MISCExploitThird Party Advisory
- https://sourceforge.net/p/sox/code/ci/master/tree/src/xa.c#l219 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-1010004
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-1010004 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1730577 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-1010004 | ||
| https://sourceforge.net/p/sox/bugs/299/ | x_refsource_MISCExploitThird Party Advisory | |
| https://sourceforge.net/p/sox/code/ci/master/tree/src/xa.c#l219 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-1010004 |
Change history (0)
No recorded changes yet.