CVE-2009-2663: libvorbis: Improper codec headers processing (DoS, ACE)

Severity: Critical

CVSS Score: 9.3

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.