Related Vulnerabilities: CVE-2017-15019  

LAME before 3.100 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.

Severity Medium

Remote Yes

Type Denial of service

Description

LAME before 3.100 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.

AVG-330 lame 3.99.5-3 3.100-1 High Fixed FS#54859

https://sourceforge.net/p/lame/bugs/477/