libsox-fmt-mp3 - SoX MP2 and MP3 format library

Property Value
Distribution Ubuntu 16.04 LTS (Xenial Xerus)
Repository Ubuntu Updates Universe amd64
Package filename libsox-fmt-mp3_14.4.1-5+deb8u4ubuntu0.1_amd64.deb
Package name libsox-fmt-mp3
Package version 14.4.1
Package release 5+deb8u4ubuntu0.1
Package architecture amd64
Package type deb
Category universe/sound
License -
Maintainer Ubuntu Developers <>
Download size 12.04 KB
Installed size 84.00 KB
SoX is the swiss army knife of sound processing.
This package contains the SoX MP2 and MP3 format library.
Read support by libmad. MP2 and MP3 write support by libtwolame and
libmp3lame respectively.


Package Version Architecture Repository
libsox-fmt-mp3_14.4.1-5+deb8u4ubuntu0.1_i386.deb 14.4.1 i386 Ubuntu Updates Universe
libsox-fmt-mp3_14.4.1-5_i386.deb 14.4.1 i386 Ubuntu Universe
libsox-fmt-mp3_14.4.1-5_amd64.deb 14.4.1 amd64 Ubuntu Universe
libsox-fmt-mp3 - - -


Name Value
libc6 >= 2.14
libid3tag0 >= 0.15.1b
libmad0 >= 0.15.1b-3
libmp3lame0 -
libsox2 >= 14.4.0
libtwolame0 -


Type URL
Binary Package libsox-fmt-mp3_14.4.1-5+deb8u4ubuntu0.1_amd64.deb
Source Package sox

2019-07-29 - Eduardo Barretto <>
sox (14.4.1-5+deb8u4ubuntu0.1) xenial-security; urgency=medium
* SECURITY UPDATE: Merge from Debian
- Fixes:
- CVE-2019-8354
- CVE-2019-8356
- CVE-2019-8357
- Fixes overwritten by Debian:
- CVE-2017-11332
- CVE-2017-11358
- CVE-2017-11359
- CVE-2017-15370
- CVE-2017-15371
- CVE-2017-15372
- CVE-2017-15642
- CVE-2017-18189
- Ignored Debian's "override_dh_strip" in debian/rules as this change was
made by mistake
2019-05-10 - Emilio Pozuelo Monfort <>
sox (14.4.1-5+deb8u4) jessie-security; urgency=medium
* Non-maintainer upload by the LTS Team.
* CVE-2019-8354, CVE-2019-8355: buffer overflow in valloc functions.
* CVE-2019-8356: stack-based buffer overflow in bitrv2().
* CVE-2019-8357: NULL pointer dereference in lsx_make_lpf().
2019-03-05 - Hugo Lefeuvre <>
sox (14.4.1-5+deb8u3) jessie-security; urgency=high
* Non-maintainer upload by the LTS Team.
* CVE-2017-15371: reachable assertion in sox_append_comment() (formats.c)
(Closes: #878809).
* CVE-2017-11359: divide-by-zero error wavwritehdr function (wav.c)
(Closes: #870328).
* CVE-2017-11332: divide-by-zero error in startread function (wav.c).
* CVE-2017-11358: invalid memory read in read_samples function (hcom.c).
2019-02-28 - Hugo Lefeuvre <>
sox (14.4.1-5+deb8u2) jessie-security; urgency=high
* Non-maintainer upload by the LTS Team.
* CVE-2017-15370: heap-based buffer overflow in the ImaExpandS function
of ima_rw.c (Closes: #878810).
* CVE-2017-15372: stack-based buffer overflow in the
lsx_ms_adpcm_block_expand_i function of adpcm.c (Closes: #878808).
* CVE-2017-18189: null pointer dereference caused by corrupt header
specifying zero channels, sending read_channels() into an infinite loop
(Closes: #881121).
* CVE-2017-15642: use-after-free in output_message, triggered by crafted
aiff file (Closes: #882144).
2019-02-24 - Adrian Bunk <>
sox (14.4.1-5+deb8u1) jessie-security; urgency=medium
* Non-maintainer upload.
* Add patches for CVE-2014-8145 to series file and really apply fixes.
Thanks to Mike Salvatore for spotting the issue. (Closes: #773720)

