5.5
CVSSv3

CVE-2017-9412

Published: 27/07/2017 Updated: 12/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote malicious users to cause a denial of service (invalid memory read and application crash) via a crafted wav file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lame project lame 3.99.5

Vendor Advisories

The unpack_read_samples function in frontend/get_audioc in LAME before 3100-1 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file ...

Exploits

LAME multiple vulnerabilities ================ Author : qflbwu =============== Introduction: ============= Following the great history of GNU naming, LAME originally stood for LAME Ain't an Mp3 Encoder LAME is an educational tool to be used for learning about MP3 encoding The goal of the LAME project is to use the open source model to improve ...