/usr/bin/play doesn't properly quote its arguments, and when fed a properly crafted 'audio file', could do some nasty things to your system as the user it is being run as.
assigned to mike
This problem is fixed and in the tree.