PT-2017-3783 · Lame+2 · Lame+2

Agostino Sarubbo

·

Published

2017-06-08

·

Updated

2023-12-29

·

CVE-2017-9872

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LAME version 3.99.5
Description The issue is related to a stack-based buffer overflow in the III dequantize sample function, which can be triggered by a crafted audio file. This can cause a denial of service, leading to an application crash. The exploitation of this issue may also have other unspecified impacts.
Recommendations For LAME version 3.99.5, consider avoiding the use of the III dequantize sample function until a patch is available. As a temporary workaround, restrict the processing of specially crafted audio files to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1793
BDU:2019-01637
CVE-2017-9872
MGASA-2017-0434
OPENSUSE-SU-2018:0543-1
OPENSUSE-SU-2018:0544-1
OPENSUSE-SU-2018_0544-1

Affected Products

Alt Linux
Lame
Suse