﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
10551	libvorbis-1.3.6	Bruce Dubbs	Bruce Dubbs	"New point version.

Fixes CVE-2018-5146 which was used against firefox's internal copy in the recent Pwn2Own contest.

[http://openwall.com/lists/oss-security/2018/03/16/4]

From the release notes at github 

* Fix CVE-2018-5146 - out-of-bounds write on codebook decoding.
* Fix CVE-2017-14632 - free() on unitialized data
* Fix CVE-2017-14633 - out-of-bounds read
* Fix bitrate metadata parsing.
* Fix out-of-bounds read in codebook parsing.
* Fix residue vector size in Vorbis I spec.
* Appveyor support
* Travis CI support
* Add secondary CMake build system.
* Build system fixes"	defect	closed	high	8.3	BOOK	SVN	medium	fixed		
