Bugzilla – Bug 1082274
VUL-0: CVE-2017-12911: mp3gain: stack memory corruption when opening a crafted MP3 file
Last modified: 2018-03-05 10:02:23 UTC
CVE-2017-12911 The "apetag.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a stack memory corruption when opening a crafted MP3 file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-12911 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12911
openSUSE:Factory has version mp3gain-1.6.1 already. Not sure if this version is still affected.
The one in Factory contains a patch with this commit https://sourceforge.net/p/mp3gain/code/ci/4963fd9aedac00bcf051617e4d88f73ad5d68942 . According to the developer, there is no public PoC to verify it though.
As reported above, apetag.c has been heavily patched, plus CVE-2017-12911 does not supply a proof of concept. I'm filing this under "hearsay" until contrary evidence emerges.