PT-2024-36815 · Theora+3 · Theora+3

Published

2024-12-25

·

Updated

2025-05-09

·

CVE-2024-56431

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Theora versions up to 1.0 7180717
Description The issue is related to an invalid negative left shift in the oc huff tree unpack function in huffdec.c within libtheora, as used in Theora. This function contains a problem that can be exploited.
Recommendations For Theora versions up to 1.0 7180717, as a temporary workaround, consider disabling the oc huff tree unpack function in huffdec.c within libtheora until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04733
CVE-2024-56431
OESA-2025-1369
OPENSUSE-SU-2025:0147-1
OPENSUSE-SU-2025:14957-1
OPENSUSE-SU-2025:15002-1
OPENSUSE-SU-2025:15009-1
OPENSUSE-SU-2025_1287-1
OPENSUSE-SU-2025_1288-1
OPENSUSE-SU-2025_1340-1
OPENSUSE-SU-2025_1365-1
SUSE-SU-2025:1287-1
SUSE-SU-2025:1288-1
SUSE-SU-2025:1340-1
SUSE-SU-2025:1365-1
SUSE-SU-2025_1340-1
SUSE-SU-2025_1365-1

Affected Products

Debian
Suse
Theora
Libtheora