LAME 3.99.5 has a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c. https://nvd.nist.gov/vuln/detail/CVE-2017-15018