Description
SoX 14.4.2 contains a division by zero vulnerability when handling WAV files that can cause program crashes. Attackers can trigger a floating point exception by providing a specially crafted WAV file that causes arithmetic errors during sound file processing.
Problem types
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/51034 (ExploitDB-51034)
sox.sourceforge.net (SoX Official SourceForge Page)
en.wikipedia.org/wiki/SoX (SoX Wikipedia Entry)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5712.php (Zero Science Lab Disclosure (ZSL-2022-5712))
www.vulncheck.com/...e-vulnerability-via-wav-file-processing (VulnCheck Advisory: SoX 14.4.2 Denial of Service Vulnerability via WAV File Processing)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.