CVE-2024-34408: Integer Overflow
Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34408?
CVE-2024-34408 is classified as a critical vulnerability due to the potential for remote code execution via crafted PAG files.
How do I fix CVE-2024-34408?
To mitigate CVE-2024-34408, users should upgrade Tencent libpag to version 4.3.52 or later where the issue is resolved.
What are the potential impacts of CVE-2024-34408?
CVE-2024-34408 can lead to integer overflow vulnerabilities that may permit attackers to execute arbitrary code on affected systems.
How can I verify if I am affected by CVE-2024-34408?
You can verify if you are affected by checking if your version of Tencent libpag is 4.3.51 or earlier.
What file types are associated with CVE-2024-34408?
CVE-2024-34408 specifically affects PAG (Portable Animated Graphics) files that can be crafted to exploit the vulnerability.