CVE-2024-56431

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/12/2024
Last modified:
25/04/2025

Description

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xiph:theora:*:*:*:*:*:*:*:* 1.2.0 (excluding)