A flaw was found in libvorbis 1.3.6. The mapping0forward function in mapping0.c file in Xiph.Org does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) via a crafted file.
References: https://gitlab.xiph.org/xiph/vorbis/issues/2335
A flaw was found in libvorbis 1.3.6. The barknoisehybridmp function in psy.c file in Xiph.Org has a stack-based buffer over-read which allows remote attackers to cause a denial of service via a crafted file.
References: https://gitlab.xiph.org/xiph/vorbis/issues/2334