Mandriva Linux Security Advisory – A vulnerability in the Speex library was found where it did not properly validate input values read from the Speex files headers. An attacker could create a malicious Speex file that would crash an application or potentially allow the execution of arbitrary code with the privileges of the application calling the Speex library. The ogg123 application in vorbis-tools is similarly affected by this issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65940/MDVSA-2008-093.txt
Source: https://packetstormsecurity.com/files/65940/Mandriva-Linux-Security-Advisory-2008-093.html