Unrated severityNVD Advisory· Published Dec 25, 2024· Updated May 7, 2025
CVE-2024-56431
CVE-2024-56431
Description
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Affected products
20- Theora/libtheoradescription
- osv-coords18 versionspkg:rpm/opensuse/libtheora&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mozjs102&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/mozjs115&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/mozjs115&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mozjs128&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mozjs52&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/mozjs60&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/mozjs78&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/mozjs102&distro=SUSE%20Package%20Hub%2015%20SP6pkg:rpm/suse/mozjs115&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/mozjs52&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/mozjs60&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/mozjs60&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/mozjs60&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/mozjs60&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/mozjs60&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/mozjs60&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/mozjs78&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6
< 1.2.0-1.1+ 17 more
- (no CPE)range: < 1.2.0-1.1
- (no CPE)range: < 102.15.1-bp156.3.3.1
- (no CPE)range: < 115.4.0-150600.3.9.1
- (no CPE)range: < 115.15.0-5.1
- (no CPE)range: < 128.9.0-2.1
- (no CPE)range: < 52.6.0-150000.3.6.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 78.15.0-150400.3.14.1
- (no CPE)range: < 102.15.1-bp156.3.3.1
- (no CPE)range: < 115.4.0-150600.3.9.1
- (no CPE)range: < 52.6.0-150000.3.6.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 60.9.0-150200.6.3.1
- (no CPE)range: < 78.15.0-150400.3.14.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.