ochufftree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
{
"isDisputed": true
}[
{
"source": "https://github.com/xiph/theora/commit/8e4808736e9c181b971306cc3f05df9e61354004",
"id": "CVE-2024-56431-5fd57ccd",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "lib/internal.h"
},
"digest": {
"line_hashes": [
"116269864363932077015583535569590980136",
"33352859868732071628436217485916996324",
"192476187473382053145762568385643970113",
"112157494868063702721238919972890642378"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]