NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lame | Jul 30, 2024 | Aug 28, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 5, 2015 |
| Suse | — | Upgrade lameUpgrade libmp3lame-develUpgrade lame-mp3rtpUpgrade libmp3lame0Upgrade lame-doc | Feb 27, 2018 | Aug 28, 2017 |
| Ubuntu | — | Upgrade lame (Ubuntu Pro) | Mar 22, 2023 | Aug 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub