* Fwd: Bug#773720: sox: CVE-2014-8145
@ 2014-12-22 18:24 Eric Wong
From: Eric Wong @ 2014-12-22 18:24 UTC (permalink / raw)
  To: dtas-all

Since dtas depends on sox: https://bugs.debian.org/773720

----- Forwarded message from Salvatore Bonaccorso <carnil@debian.org> -----

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: Bug#773720: sox: CVE-2014-8145

Source: sox
Version: 14.3.1-1
Severity: grave
Tags: security upstream


the following vulnerability was published for sox.

two heap-based buffer overflows

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2014-8145
[1] http://www.ocert.org/advisories/ocert-2014-010.html

Patches are not yet attached/referenced in the advisory, but should be
referenced in upstream git repository soon.


----- End forwarded message -----

