← Vulnerability feed

Vulnerability record · CVE-2017-9872 · published 25 June 2017

CVE-2017-9872: Lame project lame memory buffer overflow vulnerability

LLame Project · Lame

The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

7.8 CVSS 3.0 High EPSS 9.8% · top 4.6% CWE-119 · Memory buffer overflow
7.8CVSS 3.0 base score, v2 6.8
9.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9872 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11720Lame project lame divide by zero vulnerabilityThere is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.EPSS 2.5%7.8CVE-2017-15019Lame project lame null pointer dereference vulnerabilityLAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of …EPSS 1.1%7.8CVE-2017-9871Lame project lame memory buffer overflow vulnerabilityThe III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a den…EPSS 1.5%7.8CVE-2017-8419Lame project lame memory buffer overflow vulnerabilityLAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of ser…EPSS 1.5%7.5CVE-2017-13712Lame project lame null pointer dereference vulnerabilityNULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by…EPSS 1.7%5.5CVE-2017-15045Lame project lame out-of-bounds read vulnerabilityLAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, rel…EPSS 0.90%5.5CVE-2017-15046Lame project lame memory buffer overflow vulnerabilityLAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vul…EPSS 0.73%5.5CVE-2017-15018Lame project lame out-of-bounds read vulnerabilityLAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_…EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2017-9872), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.