https://seclists.org/oss-sec/2025/q2/95: CVE-2024-56431: libtheora: incorct bitwise shift in huffdec.c
Published Apr 25, 2025
·Updated
Affected Software
1 affected component
xiph libtheora<=1.2.0
Frequently Asked Questions
1
What is the severity of CVE-2024-56431?
CVE-2024-56431 has a moderate severity level.
2
What versions of libtheora are affected by CVE-2024-56431?
CVE-2024-56431 affects libtheora versions prior to 1.2.0.
3
How do I fix CVE-2024-56431?
To fix CVE-2024-56431, upgrade to libtheora version 1.2.0 or later.
4
What is the risk associated with CVE-2024-56431?
The risk associated with CVE-2024-56431 includes potential application crashes when processing specially-crafted input.
5
Which software is impacted by CVE-2024-56431?
CVE-2024-56431 impacts the Xiph libtheora software.