They don't want to fix that, and cease communication with the CVE guys?
Either the authors are terminally sick and can't do this, or they terminally suck. Time to disable that thing until this is resolved, or searching a media server who's authors care about a CVE.