High severity7.8NVD Advisory· Published May 2, 2017· Updated May 13, 2026
CVE-2017-8419
CVE-2017-8419
Description
LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- sourceforge.net/p/lame/bugs/458/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.