“Description: Ulf Harnhammar has reported two vulnerabilities
in SoX, which potentially can be exploited by malicious people to
compromise a user’s system….Successful exploitation
requires that a user is tricked into playing a malicious
“.WAV” file with a large value in a length field. The
vulnerabilities have been reported in versions 12.17.4, 12.17.3, and
12.17.2. Older versions are reportedly not affected. Solution:
Don’t play untrusted “.WAV” files.”…
NetBSD Security Advisory 2004-001: Insufficient packet validation in racoon IKE daemon