CVE-2017-15019

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
05/10/2017
Last modified:
20/04/2025

Description

LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lame_project:lame:3.99.5:*:*:*:*:*:*:*