CVE-2017-15019: Lame Project Lame
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.
Affected products
- Lame Project Lame: version 3.99.5 only
Published 2017-10-05. Last modified 2026-06-17.