516
VMScore

CVE-2021-31321

Published: 18/05/2021 Updated: 25/05/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

telegram telegram

Vendor Advisories

Debian Bug report logs - #988885 CVE-2021-31323 CVE-2021-31322 CVE-2021-31321 CVE-2021-31320 CVE-2021-31319 CVE-2021-31318 CVE-2021-31317 CVE-2021-31315 Package: src:rlottie; Maintainer for src:rlottie is Nicholas Guriev &lt;guriev-ns@yaru&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Thu, 20 May 2021 19:00:0 ...