Mandriva Linux Security Advisory – David Thiel discovered that libvorbis did not correctly verify the size of certain headers, and did not correctly clean up a broken stream. If a user were tricked into processing a specially crafted Vorbis stream, a remote attacker could possibly cause a denial of service or execute arbitrary code with the user’s privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/58699/MDKSA-2007-167.txt
Source: https://packetstormsecurity.com/files/58699/Mandriva-Linux-Security-Advisory-2007.167.html

