libvorbisfile3 - high-level API for Vorbis General Audio Compression Codec

Property Value
Distribution Ubuntu 16.04 LTS (Xenial Xerus)
Repository Ubuntu Updates Main amd64
Package filename libvorbisfile3_1.3.5-3ubuntu0.2_amd64.deb
Package name libvorbisfile3
Package version 1.3.5
Package release 3ubuntu0.2
Package architecture amd64
Package type deb
Category libs
License -
Maintainer Ubuntu Developers <>
Download size 15.50 KB
Installed size 59.00 KB
Ogg Vorbis is a fully open, non-proprietary, patent-and-royalty-free,
general-purpose compressed audio format for audio and music at fixed
and variable bitrates from 16 to 128 kbps/channel.
The Vorbisfile library provides a convenient high-level API for decoding
and basic manipulation of all Vorbis I audio streams.


Package Version Architecture Repository
libvorbisfile3_1.3.5-3ubuntu0.2_i386.deb 1.3.5 i386 Ubuntu Updates Main
libvorbisfile3_1.3.5-3_i386.deb 1.3.5 i386 Ubuntu Main
libvorbisfile3_1.3.5-3_amd64.deb 1.3.5 amd64 Ubuntu Main
libvorbisfile3 - - -


Name Value
libc6 >= 2.14
libogg0 >= 1.1.0
libvorbis0a = 1.3.5-3ubuntu0.2


Type URL
Binary Package libvorbisfile3_1.3.5-3ubuntu0.2_amd64.deb
Source Package libvorbis

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install libvorbisfile3 deb package:
    # sudo apt-get install libvorbisfile3




2018-03-21 - Marc Deslauriers <>
libvorbis (1.3.5-3ubuntu0.2) xenial-security; urgency=medium
* SECURITY UPDATE: out-of-bounds write in codebook decoding
- debian/patches/CVE-2018-5146.patch: fix codebook decoding in
- CVE-2018-5146
2018-02-13 - Leonidas S. Barbosa <>
libvorbis (1.3.5-3ubuntu0.1) xenial-security; urgency=medium
* SECURITY UPDATE: Remote code execution
- debian/patches/CVE-2017-14632.patch: don't clear opb in
- CVE-2017-14632
* SECURITY UPDATE: out-of-bounds array read
- debian/patches/CVE-2017-14633.patch: don't allow for more than
256 channels in lib/info.c.
- CVE-2017-14633
2016-02-11 - Petter Reinholdtsen <>
libvorbis (1.3.5-3) unstable; urgency=medium
* Replace Peter Samuelson with Ralph Giles as uploader.  Thank you
Peter for all past work.
* Fix autopkgtest script by redirecting stderr to log file.
* Add new autopkgtest script test-coupling-segfault to detect if
bug #772877 is present.
2016-02-07 - Petter Reinholdtsen <>
libvorbis (1.3.5-2) unstable; urgency=medium
* Add build-essential to the list of autopkgtest dependencies to get gcc.
2016-02-06 - Petter Reinholdtsen <>
libvorbis (1.3.5-1) unstable; urgency=low
[ Martin Steghöfer ]
* New upstream version 1.3.5. (Closes: #798960)
[ Petter Reinholdtsen ]
* Added simple autopkgtest script running the examples.
2015-09-22 - Petter Reinholdtsen <>
libvorbis (1.3.4-3) unstable; urgency=low
[ Martin Steghöfer ]
* Fix crash on corrupt input file (invalid mode index). (Closes: #774516)
* Take into account error codes returned from
"vorbis_packet_blocksize" in "_initial_pcmoffset" (follow-up
problem related to #774516).  Thanks to Timothy B. Terriberry
* Fix segmentation fault on two subsequent seeks to 0. (Closes: #782831)
[ Petter Reinholdtsen ]
* Add debian/gbp.conf to enforce the user of pristine-tar.
2014-11-03 - Petter Reinholdtsen <>
libvorbis (1.3.4-2) unstable; urgency=low
[ Martin Steghöfer ]
* Add sampling rate sanity check to avoid invalid memory access.
(Closes: #716613)
2014-10-24 - Petter Reinholdtsen <>
libvorbis (1.3.4-1) unstable; urgency=medium
[ Martin Steghöfer ]
* New upstream version 1.3.4. (Closes: #739722)
* Rebased patches and dropped cve-2012-0444 patch that is included
in new upstream.
* Removed lintian override for tag
"using-first-person-in-description". Lintian has improved and
doesn't report this false positive any longer.
* Upgrade Standards-Version to 3.9.6. No changes necessary.
* Clean-up: Removed references to the old libvorbis0 package, it
hasn't been in any release for ages.
2014-10-24 - Petter Reinholdtsen <>
libvorbis (1.3.2-2) unstable; urgency=medium
[ Martin Steghöfer ]
* Format patches for gbp-pq.
* Updated VCS meta information to list git repository.
[ Petter Reinholdtsen ]
* Drop John Francesco Ferlito and add me and Martin Steghöfer as
* Updated standards-version from 3.9.1 to 3.9.6.
[ Martin Steghöfer ]
* Fix lintian warning
"description-synopsis-starts-with-article". Make sure the synopsis
of the package description meets the formula "The package [name]
provides {a,an,the,some} [synopsis]."
* Override lintian tag "license-problem-non-free-RFC-BCP78" for RFC
5215 - it has a dual license.
* Fix lintian warning "wrong-name-for-upstream-changelog" by using
"dh_installchangelogs" instead of "dh_installdocs" for the
upstream changelog.

