CVE-2017-9869
MEDIUMLAME 3.99.5 - Denial of Service via Crafted Audio File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9869. PoCs published by Agostino Sarubbo.
AI-analyzed exploit summary The exploit demonstrates a global buffer overflow in LAME MP3 encoder (version 3.99.5) via a crafted MP3 file, leading to a crash during decoding. The issue is triggered in the `II_step_one` function in `layer2.c` due to an out-of-bounds read.
Description
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
Exploits (1)
The exploit demonstrates a global buffer overflow in LAME MP3 encoder (version 3.99.5) via a crafted MP3 file, leading to a crash during decoding. The issue is triggered in the `II_step_one` function in `layer2.c` due to an out-of-bounds read.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H