Related Vulnerabilities: CVE-2017-15018  

A heap-based buffer over-read vulnerability has been discovered in LAME before 3.100 in the k_34_4 function in vbrquantize.c while handling a malformed file.

Severity Medium

Remote Yes

Type Denial of service

Description

A heap-based buffer over-read vulnerability has been discovered in LAME before 3.100 in the k_34_4 function in vbrquantize.c while handling a malformed file.

AVG-437 lame 3.99.5-3 3.99.5-4 Medium Fixed FS#55889

09 Oct 2017 ASA-201710-11 AVG-437 lame Medium denial of service

https://sourceforge.net/p/lame/bugs/480/