These are all security issues fixed in the libvorbis-devel-1.3.5-2.1 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "libvorbis-devel": "1.3.5-2.1", "libvorbis-devel-32bit": "1.3.5-2.1", "libvorbisfile3": "1.3.5-2.1", "libvorbis-doc": "1.3.5-2.1", "libvorbis0-32bit": "1.3.5-2.1", "libvorbisfile3-32bit": "1.3.5-2.1", "libvorbisenc2-32bit": "1.3.5-2.1", "libvorbisenc2": "1.3.5-2.1", "libvorbis0": "1.3.5-2.1" } ] }