vendor:
SoX
by:
Serkan Akpolat
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: SoX
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Slackware 9.1
2004
POC Exploit for SoX Stack Overflow Vulnerability
This is a proof-of-concept exploit for the SoX stack overflow vulnerability. The exploit creates a malicious WAV file named britney.wav, which triggers the vulnerability when played using the 'play' command. The exploit payload consists of shellcode that opens a shell on the target system. The vulnerability was discovered by Ulf Harnhammar and the exploit was created by Serkan Akpolat. The exploit has been tested on Slackware 9.1. The vulnerability allows an attacker to execute arbitrary code on the target system.
Mitigation:
Apply the latest patches or updates for SoX. Avoid playing untrusted or malicious WAV files.