383
VMScore

CVE-2021-31323

Published: 18/05/2021 Updated: 25/05/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

telegram telegram

Vendor Advisories

Debian Bug report logs - #988885 CVE-2021-31323 CVE-2021-31322 CVE-2021-31321 CVE-2021-31320 CVE-2021-31319 CVE-2021-31318 CVE-2021-31317 CVE-2021-31315 Package: src:rlottie; Maintainer for src:rlottie is Nicholas Guriev &lt;guriev-ns@yaru&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Thu, 20 May 2021 19:00:0 ...