References 1 https://security.archlinux.org/CVE-2015-9101 references 2 2 https://blogs.gentoo.org/ago/2017/06/17/lame-heap-based-buffer-overflow-in-fill_buffer_resample-util-c/ references 4 as same issue 3 https://security-tracker.debian.org/tracker/CVE-2015-9101 references 4 as fixing issue 4 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777161 references 5 as already proving fix for issue 5 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775959 Patch 6 http://lame.cvs.sourceforge.net/viewvc/lame/lame/libmp3lame/util.c?revision=1.157&view=markup references 5 7 http://lame.cvs.sourceforge.net/viewvc/lame/lame/libmp3lame/util.c?r1=1.156&r2=1.157&view=patch patch for 6 7 https://sources.debian.net/src/lame/3.99.5%2Brepack1-9/debian/patches/int_resample_ratio.patch/ references 5 equivalent code to 7 Proof Of Concept 8 https://github.com/asarubbo/poc/blob/master/00292-lame-heapoverflow-fill_buffer_resample test file referenced by 2 test command: lame -f -V 9 00292-lame-heapoverflow-fill_buffer_resample /dev/null