lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 46288d12d1c30d08fbeffd05abc079f57a43a2d4 |