The tags in the OGG Vorbis files are handled by the CPLI_ReadTag_OGG
function which uses sscanf for storing the tag's name and its value in
two stack buffers but the lack of size limiters in the format argument
results in a buffer-overflow.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.