Ubuntu Security Notice 498-1 – David Thiel discovered that libvorbis did not correctly verify the size of certain headers, and did not correctly clean up a broken stream. If a user were tricked into processing a specially crafted Vorbis stream, a remote attacker could execute arbitrary code with the user’s privileges.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/58640/USN-498-1.txt
Source: https://packetstormsecurity.com/files/58640/Ubuntu-Security-Notice-498-1.html

