UBUNTU-CVE-2021-31322
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-31322
UBUNTU-CVE-2021-31322
Summary:
Details: Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
References: https://ubuntu.com/security/CVE-2021-31322, https://www.shielder.it/advisories/telegram-rlottie-lotgradient-populate-heap-buffer-overflow/, https://www.cve.org/CVERecord?id=CVE-2021-31322, https://ubuntu.com/security/notices/USN-7198-1
Affected packages
Package
Name: rlottie
Purl: pkg:deb/ubuntu/rlottie@0~git20200305.a717479+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
