LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://sourceforge.net/p/lame/bugs/477/ | third party advisory exploit |