Medium severity5.5NVD Advisory· Published Jun 25, 2017· Updated May 13, 2026
CVE-2015-9099
CVE-2015-9099
Description
The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.
Affected products
1- cpe:2.3:a:lame_project:lame:3.99.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/99279nvdThird Party AdvisoryVDB Entry
- bugs.debian.org/cgi-bin/bugreport.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.