A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.
https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332
https://github.com/xiph/vorbis-tools/archive/refs/tags/v1.4.3.tar.gz