Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <tencent_43AA27D65C46DEB244310CDB@qq.com>
Date: Fri, 25 Apr 2025 15:17:52 +0800
From: "xiaolin" <dongxiaolin@...pin.org>
To: "oss-security" <oss-security@...ts.openwall.com>
Subject: CVE-2024-56431: libtheora: incorrect bitwise shift in huffdec.c

Severity:&nbsp;
- moderate


Affected versions:
- libtheora through 1.2.0


Fixed software:
- v1.2.0


Description:
A flaw was found in Theora (libtheora). An incorrect bitwise shift may be triggered via specially-crafted input, potentially resulting in an application crash.


-------------------------------------------------------------
References:
https://github.com/advisories/GHSA-8xp8-gmmj-xc8w
https://github.com/UnionTech-Software/openfhe-PoC
https://gitlab.xiph.org/xiph/theora/-/merge_requests/28
https://gitlab.xiph.org/xiph/theora/-/commit/5665f86b8fd8345bb09469990e79221562ac204b

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.