vorbis-tools was updated to fix a buffer overflow in aiff_open() that could be triggered by opening prepared malicious files. (CVE-2015-6749, bsc#943795).
{ "binaries": [ { "vorbis-tools-lang": "1.4.0-26.1", "vorbis-tools": "1.4.0-26.1" } ] }
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1765-1.json"