oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.06093}

epss

{'score': 0.07751}


Fri, 11 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.07751}

epss

{'score': 0.06093}


Sat, 26 Apr 2025 05:45:00 +0900

Type Values Removed Values Added
References

Sat, 26 Apr 2025 04:15:00 +0900

Type Values Removed Values Added
Description oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
References

Sat, 26 Apr 2025 03:45:00 +0900

Type Values Removed Values Added
References

Tue, 22 Apr 2025 02:15:00 +0900

Type Values Removed Values Added
First Time appeared Xiph theora
CPEs cpe:2.3:a:xiph:libtheora:*:*:*:*:*:*:*:* cpe:2.3:a:xiph:theora:*:*:*:*:*:*:*:*
Vendors & Products Xiph libtheora
Xiph theora

Wed, 09 Apr 2025 22:30:00 +0900

Type Values Removed Values Added
First Time appeared Xiph
Xiph libtheora
CPEs cpe:2.3:a:xiph:libtheora:*:*:*:*:*:*:*:*
Vendors & Products Xiph
Xiph libtheora

Tue, 25 Mar 2025 01:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 19 Feb 2025 07:45:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Wed, 01 Jan 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 26 Dec 2024 10:15:00 +0900

Type Values Removed Values Added
Title libtheora: incorrect bitwise shift in huffdec.c
Weaknesses CWE-1335
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Thu, 26 Dec 2024 02:15:00 +0900

Type Values Removed Values Added
Description oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-07T19:45:58.528Z

Reserved: 2024-12-24T00:00:00.000Z

Link: CVE-2024-56431

cve-icon Vulnrichment

Updated: 2025-04-25T20:03:14.642Z

cve-icon NVD

Status : Modified

Published: 2024-12-25T17:15:05.510

Modified: 2025-04-25T20:15:38.220

Link: CVE-2024-56431

cve-icon Redhat

Severity : Low

Publid Date: 2024-12-25T00:00:00Z

Links: CVE-2024-56431 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses