CVE-2017-8374: Underbit Mad Libmad

Medium severity, CVSS 5.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

Affected products

  • Underbit Mad Libmad: version 0.15.1b only

Published 2017-05-01. Last modified 2026-06-17.