There is a stack-based buffer overflow in the lsxmsadpcmblockexpand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15372.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.4.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]