Debian 10225 Published by

A sox security update has been released for Debian GNU/Linux 11.



DSA 5356-1: sox security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-5356-1 security@debian.org
  https://www.debian.org/security/ Moritz Muehlenhoff
February 20, 2023   https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : sox
CVE ID : CVE-2021-3643 CVE-2021-23159 CVE-2021-23172 CVE-2021-23210
CVE-2021-33844 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651
Debian Bug : 1010374 1012138 1012516 1021133 1021134 1021135

Multiple security issues were discovered in Sox, the Swiss Army knife of
sound processing programs, which could result in denial of service or
potentially the execution of arbitrary code if a malformed audio file
is processed.

For the stable distribution (bullseye), these problems have been fixed in
version 14.4.2+git20190427-2+deb11u1.

We recommend that you upgrade your sox packages.

For the detailed security status of sox please refer to
its security tracker page at:
  https://security-tracker.debian.org/tracker/sox

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:   https://www.debian.org/security/