CVE-2015-9099

MEDIUM5.5EPSS 0.38%
發布日:2017/6/25修改日:2025/12/3
也稱為:ALPINE-CVE-2015-9099DEBIAN-CVE-2015-9099

描述

The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.5CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

參考連結(2)