ochufftree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
{ "isDisputed": true }
{ "vanir_signatures": [ { "target": { "file": "lib/internal.h" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "116269864363932077015583535569590980136", "33352859868732071628436217485916996324", "192476187473382053145762568385643970113", "112157494868063702721238919972890642378" ] }, "id": "CVE-2024-56431-5fd57ccd", "signature_version": "v1", "signature_type": "Line", "source": "https://github.com/xiph/theora/commit/8e4808736e9c181b971306cc3f05df9e61354004" } ] }