UBUNTU-CVE-2021-31319
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-31319
UBUNTU-CVE-2021-31319
Summary:
Details: Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
References: https://ubuntu.com/security/CVE-2021-31319, https://www.shielder.it/advisories/telegram-rlottie-lotgradient-populate-integer-overflow/, https://www.cve.org/CVERecord?id=CVE-2021-31319, https://ubuntu.com/security/notices/USN-7198-1
Affected packages
Package
Name: rlottie
Purl: pkg:deb/ubuntu/rlottie@0~git20200305.a717479+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
