← Vulnerability feed

Vulnerability record · CVE-2017-15045 · published 6 October 2017

CVE-2017-15045: Lame project lame out-of-bounds read vulnerability

LLame Project · Lame

LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410.

5.5 CVSS 3.0 Medium EPSS 0.90% · top 42.0% CWE-125 · Out-of-bounds read
5.5CVSS 3.0 base score, v2 4.3
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-15045 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11720Lame project lame divide by zero vulnerabilityThere is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.EPSS 2.5%7.8CVE-2017-15019Lame project lame null pointer dereference vulnerabilityLAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of …EPSS 1.1%7.8CVE-2017-9871Lame project lame memory buffer overflow vulnerabilityThe III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a den…EPSS 1.5%7.8CVE-2017-9872Lame project lame memory buffer overflow vulnerabilityThe III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to ca…EPSS 9.8%7.8CVE-2017-8419Lame project lame memory buffer overflow vulnerabilityLAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of ser…EPSS 1.5%7.5CVE-2017-13712Lame project lame null pointer dereference vulnerabilityNULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by…EPSS 1.7%5.5CVE-2017-15046Lame project lame memory buffer overflow vulnerabilityLAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vul…EPSS 0.73%5.5CVE-2017-15018Lame project lame out-of-bounds read vulnerabilityLAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_…EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2017-15045), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.