CVE-2017-9872 describes a stack-based buffer overflow in the III_dequantize_sample function within mpglib, specifically affecting LAME 3.99.5 and other products utilizing libmpgdecoder.a. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk of denial of service and potential for other unspecified impacts, triggered by a crafted audio file requiring user interaction. While not listed in CISA's KEV catalog or actively exploited, public exploit code exists (EDB-42259), though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.99.5CPE matchmatch criteria | cpe:2.3:a:lame_project:lame:3.99.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.