CVE-2024-56431: libtheora: incorct bitwise shift in huffdec.c
Published Dec 25, 2024
·Updated
ochufftreeunpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Affected Software
2 affected components
Theora libtheora<=1.0
xiph Theora<1.2.0
Event History
Dec 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56431?
CVE-2024-56431 is classified as a medium severity vulnerability affecting libtheora.
2
Which versions of libtheora are affected by CVE-2024-56431?
CVE-2024-56431 affects all versions of libtheora up to and including version 1.0.
3
How do I fix CVE-2024-56431?
To fix CVE-2024-56431, update to the latest version of libtheora that addresses this vulnerability.
4
What is the nature of the vulnerability in CVE-2024-56431?
CVE-2024-56431 is caused by an invalid negative left shift in the oc_huff_tree_unpack function.
5
Are there any known exploits for CVE-2024-56431?
As of now, there are no publicly documented exploits for CVE-2024-56431, but users should remain vigilant.