Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-56431

Published: December 26, 2024Last modified: June 24, 2025

Description

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift.

Severity score breakdown

ParameterValue
Base score9.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Notes

Possibly not affected, as this CVE is disputed: https://www.openwall.com/lists/oss-security/2025/04/25/6 Fixed in 1.2.0 https://gitlab.xiph.org/xiph/theora/-/commit/5665f86b8fd8345bb09469990e79221562ac204b

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibtheoraUnknown (1.1.1-r16)
StreamlibtheoraUnknown (1.1.1-r16)

References

ON THIS PAGE