ochufftree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libtheora-bin", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheora-bin-dbgsym", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheora-dev", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheora-doc", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheora0", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheora0-dbgsym", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheoradec1", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheoradec1-dbgsym", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheoraenc1", "binary_version": "1.2.0~alpha1+dfsg-6" }, { "binary_name": "libtheoraenc1-dbgsym", "binary_version": "1.2.0~alpha1+dfsg-6" } ] }