Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 14 Mar 2023 21:16:52 +0100
From: Steffen Nurpmeso <steffen@...oden.eu>
To: Helmut Grohne <helmut@...divi.de>
Cc: oss-security@...ts.openwall.com
Subject: Re: Re: sox: patches for old vulnerabilities

Hello Helmut, list, and special greetings to the happy moderator,

Steffen Nurpmeso wrote in
 <20230314191132.qDz3u%steffen@...oden.eu>:
 ...
 |Helmut Grohne wrote in
 | <20230314110138.GA1192267@...divi.de>:
 ||On Fri, Feb 03, 2023 at 09:44:47PM +0100, Helmut Grohne wrote:
 ||>  * CVE-2021-33844
 ||
 ||The original fix for this issue would cause a regression. After applying
 ||it, sox would be unable to decode WAV GSM files. This has been reported
 ...
 |You have chosen not to update to latest possible git(?).
 ...
 ||From: Helmut Grohne <helmut@...divi.de>
 ||Subject: wav: reject 0 bits per sample to avoid division by zero
 ||Bug: https://sourceforge.net/p/sox/bugs/349/
 ||Bug-Debian: https://bugs.debian.org/1021135
 | ...
 ||--- a/src/wav.c
 ||+++ b/src/wav.c
 ...

So then my take for the git variant would be as attached.
It compiles, but no GSM here.
(It seems our dear sox developer was out of dynamic tension when
he did that, overall.)

Ciao,

P.S.: on OpenBSD they committed additional code hunks; i still
have not looked into this, but have it on that stairway to over
the clowds to work through.

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)

View attachment "sox-git.patch" of type "text/x-diff" (2475 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.