oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.06093}

epss

{'score': 0.07751}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.07751}

epss

{'score': 0.06093}


Fri, 25 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
References

Fri, 25 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Description oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
References

Fri, 25 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
References

Mon, 21 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Xiph theora
CPEs cpe:2.3:a:xiph:libtheora:*:*:*:*:*:*:*:* cpe:2.3:a:xiph:theora:*:*:*:*:*:*:*:*
Vendors & Products Xiph libtheora
Xiph theora

Wed, 09 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Xiph
Xiph libtheora
CPEs cpe:2.3:a:xiph:libtheora:*:*:*:*:*:*:*:*
Vendors & Products Xiph
Xiph libtheora

Mon, 24 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 18 Feb 2025 22:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Tue, 31 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 26 Dec 2024 01:15:00 +0000

Type Values Removed Values Added
Title libtheora: incorrect bitwise shift in huffdec.c
Weaknesses CWE-1335
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Wed, 25 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Description oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-07T19:45:58.528Z

Reserved: 2024-12-24T00:00:00.000Z

Link: CVE-2024-56431

cve-icon Vulnrichment

Updated: 2025-04-25T20:03:14.642Z

cve-icon NVD

Status : Modified

Published: 2024-12-25T17:15:05.510

Modified: 2025-04-25T20:15:38.220

Link: CVE-2024-56431

cve-icon Redhat

Severity : Low

Publid Date: 2024-12-25T00:00:00Z

Links: CVE-2024-56431 - Bugzilla

cve-icon OpenCVE Enrichment

No data.