CVE-2024-34408

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-34408
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-34408.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-34408
Published
2024-05-03T06:15:13.883Z
Modified
2025-11-15T19:06:27.922236Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.

References

Affected packages

Git / github.com/tencent/libpag

Affected ranges

Type
GIT
Repo
https://github.com/tencent/libpag
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v.*

v.3.2.7.40

v3.*

v3.2.7.37

v4.*

v4.1.8
v4.3.3
v4.3.33
v4.3.43
v4.3.45
v4.3.47
v4.3.51