Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-56431

Опубликовано: 25 дек. 2024
Источник: redhat
CVSS3: 3.3
EPSS Средний

Описание

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

A flaw was found in Theora (libtheora). An incorrect bitwise shift may be triggered via specially-crafted input, potentially resulting in an application crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libtheoraFix deferred
Red Hat Enterprise Linux 6libtheoraOut of support scope
Red Hat Enterprise Linux 7firefoxOut of support scope
Red Hat Enterprise Linux 7libtheoraOut of support scope
Red Hat Enterprise Linux 7thunderbirdOut of support scope
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 8libtheoraFix deferred
Red Hat Enterprise Linux 8thunderbirdFix deferred
Red Hat Enterprise Linux 9firefoxFix deferred
Red Hat Enterprise Linux 9firefox:flatpak/firefoxFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1335
https://bugzilla.redhat.com/show_bug.cgi?id=2334093libtheora: incorrect bitwise shift in huffdec.c

EPSS

Процентиль: 94%
0.13935
Средний

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

CVSS3: 9.8
nvd
около 1 года назад

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

CVSS3: 9.8
debian
около 1 года назад

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 71 ...

suse-cvrf
8 месяцев назад

Security update for mozjs102

suse-cvrf
8 месяцев назад

Security update for mozjs60

EPSS

Процентиль: 94%
0.13935
Средний

3.3 Low

CVSS3