Description
The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
In plain language
AI Worth attentionA flaw in how some MP3-related software decodes audio can let a remote attacker crash your app when a user opens a specially crafted audio file; if you use affected LAME/libmpgdecoder builds, you should update.
CVE-2017-9872 is a stack-based buffer overflow in the mpg decoder (mpglib’s III_dequantize_sample) as packaged in libmpgdecoder.a used by LAME 3.99.5 and other products; a crafted audio file can trigger a crash when the file is opened.
What to do now
- Check whether your installed LAME/libmpgdecoder comes from LAME 3.99.5 (or is linked against libmpgdecoder.a that includes the vulnerable mpg decoder code).
- If you find it’s affected, plan an upgrade to LAME 3.100-2 (or a later version).
- For Debian systems, upgrade the corresponding LAME package to the fixed version provided by your Debian updates.
- After upgrading, test your audio/file-processing paths with normal files and watch for crashes when decoding MP3s.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-9872 and every CVE in our database. Create a free account — no credit card required.
Create Free Account