Source: libtheora
Version: 1.2.0+dfsg-6
Severity: important
Tags: security upstream
Forwarded: https://github.com/xiph/theora/issues/24
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libtheora.

CVE-2026-5673[0]:
| A flaw was found in libtheora. This heap-based out-of-bounds read
| vulnerability exists within the AVI (Audio Video Interleave) parser,
| specifically in the avi_parse_input_file() function. A local
| attacker could exploit this by tricking a user into opening a
| specially crafted AVI file containing a truncated header sub-chunk.
| This could lead to a denial-of-service (application crash) or
| potentially leak sensitive information from the heap.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5673
    https://www.cve.org/CVERecord?id=CVE-2026-5673
[1] https://github.com/xiph/theora/issues/24

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to