NULL pointer dereference in lame - CVE-2017-13712
Published: August 28, 2017 / Updated: August 8, 2020
lame
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument. A remote attacker can perform a denial of service (DoS) attack.