Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.445
EPSS Ranking 97.4%