CVE-2017-9872
HIGHLAME 3.99.5 - Stack-Based Buffer Overflow in III_dequantize_sample
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9872. PoCs published by Agostino Sarubbo.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in the `III_dequantize_sample` function of LAME MP3 encoder version 3.99.5, triggered by a malformed MP3 file. The overflow occurs during MP3 decoding, leading to a crash and potential arbitrary code execution.
Description
The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in the `III_dequantize_sample` function of LAME MP3 encoder version 3.99.5, triggered by a malformed MP3 file. The overflow occurs during MP3 decoding, leading to a crash and potential arbitrary code execution.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H