CVE-2024-34408: Tencent Libpag

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.

Affected products

  • Tencent Libpag: up to and including 4.3.51

Published 2024-05-03. Last modified 2026-06-17.