Bugzilla – Bug 1082329
VUL-0: CVE-2015-9099: lame: The lame_init_params function in lame.c in libmp3lame.a allows remote attackers to cause a denial of service
Last modified: 2018-02-22 15:46:36 UTC
CVE-2015-9099 The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-9099 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9099
we have this already in Leap and Factory