Debian Security Advisory 1591-1 – Several local (remote) vulnerabilities have been discovered in libvorbis, a library for the Vorbis general-purpose compressed audio codec. libvorbis does not properly handle a zero value which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow. Integer overflow in libvorbis allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow. Integer overflow in libvorbis allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file which triggers a heap overflow.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66933/dsa-1591-1.txt
Source: https://packetstormsecurity.com/files/66933/Debian-Linux-Security-Advisory-1591-1.html

