Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5673

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

Отчет

Moderate: A heap-based out-of-bounds read flaw in libtheora's AVI parser can lead to a denial-of-service or information leak. Exploitation requires a local attacker to trick a user into opening a specially crafted AVI file.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libtheoraFix deferred
Red Hat Enterprise Linux 6libtheoraFix deferred
Red Hat Enterprise Linux 7libtheoraFix deferred
Red Hat Enterprise Linux 8libtheoraFix deferred
Red Hat Enterprise Linux 9libtheoraFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2455340libtheora: libtheora: Denial of Service or Information Disclosure via malformed AVI file processing

EPSS

Процентиль: 2%
0.00012
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
8 дней назад

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

CVSS3: 5.6
nvd
8 дней назад

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

CVSS3: 5.6
debian
8 дней назад

A flaw was found in libtheora. This heap-based out-of-bounds read vuln ...

CVSS3: 5.6
github
8 дней назад

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

EPSS

Процентиль: 2%
0.00012
Низкий

5.6 Medium

CVSS3