Debian Libtheora vulnerabilities
2 known vulnerabilities affecting debian/libtheora.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-56431P3LOWCVSS 9.8fixed in libtheora 1.2.0~alpha1+dfsg-6 (forky)2024
CVE-2024-56431 [CRITICAL] CVE-2024-56431: libtheora - oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has ...
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.2.0~alpha1+dfsg-6)
sid: resolved (fixed in
debian
CVE-2009-3389P3CRITICALCVSS 9.3fixed in libtheora 1.1 (bookworm)2009
CVE-2009-3389 [CRITICAL] CVE-2009-3389: libtheora - Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla ...
Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.
Scope: local
bookworm: resolved (fixed in 1.1)
bullseye: resolved (fixed in 1.1)
forky:
debian