CVE-2017-13712: Lame Project Lame

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument.

Affected products

Published 2017-08-28. Last modified 2026-06-17.