Tencent.libpag is vulnerable to Heap-based Buffer Overflow
30
Low Risk
Affected versions of the package are vulnerable to a heap-based buffer overflow due to incorrect use of strlen in DecodeStream::readUTF8String(), which leads to crashes and potential Denial of Service.
You are affected if you are using a version that falls within the vulnerable range.
Tencent.libpag is vulnerable to Heap-based Buffer Overflow in versions 4.0.5 - 4.4.0.
Upgrade the Tencent.libpag library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant