Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-56431

Опубликовано: 25 дек. 2024
Источник: debian

Описание

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libtheorafixed1.2.0~alpha1+dfsg-6package
libtheoranot-affectedbookwormpackage
libtheoranot-affectedbullseyepackage

Примечания

  • https://github.com/UnionTech-Software/libtheora-CVE-2024-56431-PoC

  • https://github.com/advisories/GHSA-8xp8-gmmj-xc8w

  • https://github.com/xiph/theora/issues/18

  • https://gitlab.xiph.org/xiph/theora/-/merge_requests/28

  • Fixed by: https://gitlab.xiph.org/xiph/theora/-/commit/5665f86b8fd8345bb09469990e79221562ac204b (v1.2.0beta1)

  • No security impact

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

CVSS3: 3.3
redhat
около 1 года назад

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

CVSS3: 9.8
nvd
около 1 года назад

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

suse-cvrf
8 месяцев назад

Security update for mozjs102

suse-cvrf
8 месяцев назад

Security update for mozjs60