Intel

AIKIDO-2024-10218

Tencent.libpag is vulnerable to Heap-based Buffer Overflow

Heap-based Buffer Overflow Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 14, 2024

30

Low Risk

This Affects:

c++Tencent.libpag
4.0.5 - 4.4.0
Fixed in 4.4.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to a heap-based buffer overflow due to incorrect use of strlen in DecodeStream::readUTF8String(), which leads to crashes and potential Denial of Service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Tencent.libpag is vulnerable to Heap-based Buffer Overflow in versions 4.0.5 - 4.4.0.

How to fix this

Upgrade the Tencent.libpag library to the patch version.