Input validation error in Theora - CVE-2024-56431

 

Input validation error in Theora - CVE-2024-56431

Published: April 4, 2025


Vulnerability identifier: #VU106993
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-56431
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the oc_huff_tree_unpack() function in in huffdec.c. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Theora
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Package Hub 15
Desktop Applications Module
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
libtheora-debuginfo
libtheora-debugsource
libtheora-devel
theora-tools
libtheora-help
libtheora
libtheora-doc
libtheora-devel-docs
mozjs52-debugsource
libmozjs-52-debuginfo
mozjs52-devel
libmozjs-52
mozjs52-debuginfo
mozjs52
libmozjs-60-debuginfo
mozjs60-debugsource
libmozjs-60
mozjs60-devel
mozjs60-debuginfo
mozjs60
libmozjs-78-0-debuginfo
mozjs78
mozjs78-devel
mozjs78-debugsource
libmozjs-78-0
mozjs78-debuginfo
mozjs115
mozjs115-debuginfo
mozjs115-debugsource
libmozjs-115-0
mozjs115-devel
libmozjs-115-0-debuginfo
SmartFabric Manager

How to mitigate CVE-2024-56431

Install updates from vendor's website.

Theora - update to 1.2.0
libtheora-debuginfo - update to 1.1.1-25
libtheora-debugsource - update to 1.1.1-25
libtheora-devel - update to 1.1.1-25
theora-tools - update to 1.1.1-25
libtheora-help - update to 1.1.1-25
libtheora - update to 1.1.1-25
libtheora-doc - update to 1.2.0-1
libtheora-devel-docs - update to 1.2.0-1
theora-tools - update to 1.2.0-1
libtheora-devel - update to 1.2.0-1
libtheora - update to 1.2.0-1
SmartFabric Manager - update to 1.3.0
mozjs52-debugsource - update to 52.6.0-150000.3.6.1
libmozjs-52-debuginfo - update to 52.6.0-150000.3.6.1
mozjs52-devel - update to 52.6.0-150000.3.6.1
libmozjs-52 - update to 52.6.0-150000.3.6.1
mozjs52-debuginfo - update to 52.6.0-150000.3.6.1
mozjs52 - update to 52.6.0-150000.3.6.1
libmozjs-60-debuginfo - update to 60.9.0-150200.6.3.1
mozjs60-debugsource - update to 60.9.0-150200.6.3.1
libmozjs-60 - update to 60.9.0-150200.6.3.1
mozjs60-devel - update to 60.9.0-150200.6.3.1
mozjs60-debuginfo - update to 60.9.0-150200.6.3.1
mozjs60 - update to 60.9.0-150200.6.3.1
libmozjs-78-0-debuginfo - update to 78.15.0-150400.3.14.1
mozjs78 - update to 78.15.0-150400.3.14.1
mozjs78-devel - update to 78.15.0-150400.3.14.1
mozjs78-debugsource - update to 78.15.0-150400.3.14.1
libmozjs-78-0 - update to 78.15.0-150400.3.14.1
mozjs78-debuginfo - update to 78.15.0-150400.3.14.1
mozjs115 - update to 115.4.0-150600.3.9.1
mozjs115-debuginfo - update to 115.4.0-150600.3.9.1
mozjs115-debugsource - update to 115.4.0-150600.3.9.1
libmozjs-115-0 - update to 115.4.0-150600.3.9.1
mozjs115-devel - update to 115.4.0-150600.3.9.1
libmozjs-115-0-debuginfo - update to 115.4.0-150600.3.9.1

External References

Related Security Bulletins