DSA-1584 libfishsound - buffer overflow
It was discovered that libfishsound, a simple programming interface that
wraps Xiph.Org audio codecs, didn’t correctly handle negative values in
a particular header field. This could allow malicious files to execute
arbitary code.
Read the full story: DSA-1584 libfishsound - buffer overflow: http://www.debian.org/security/2008/dsa-1584