Family: Fedora Local Security Checks --> Category: infos
Fedora Core 1 2004-235: sox Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the sox package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2004-235 (sox).
SoX (Sound eXchange) is a sound file format converter SoX can convert
between many different digitized sound formats and perform simple
sound manipulation functions, including sound effects.
Updated sox packages that fix buffer overflows in the WAV file handling
code are now available.
Buffer overflows existed in the parsing of WAV file header fields. It
was possible that a malicious WAV file could have caused arbitrary code to
be executed when the file was played or converted.
Solution : http://www.fedoranews.org/updates/FEDORA-2004-235.shtml
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.