SUSE has released security update for libid3tag to fix the vulnerabilities.
SUSE Linux Enterprise Software Development Kit 12-SP3
SUSE Linux Enterprise Software Development Kit 12-SP2
SUSE Linux Enterprise Desktop 12-SP3
SUSE Linux Enterprise Desktop 12-SP2
This vulnerability can be used to cause a limited denial of service in the form of interruptions in resource availability.
Upgrade to the latest packages which contain a patch. To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product.
To install packages using the command line interface, use the command “yum update”.
Refer to SUSE security advisory SUSE-SU-2018:0722-1 to address this issue and obtain further details.
Following are links for downloading patches to fix the vulnerabilities: