Описание
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads.
This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
A flaw was found in rlottie. This uncontrolled recursion vulnerability allows a local attacker to cause a denial of service (DoS) by providing specially crafted serialized data with nested payloads. Successful exploitation requires user interaction to process the malicious data.
Отчет
The rlottie library is shipped in Fedora and EPEL community distributions. The uncontrolled recursion vulnerability can be triggered by processing specially crafted serialized data with nested payloads, leading to a denial of service.
Меры по смягчению последствий
Update rlottie to a version that includes the upstream fix commit 8de0d9e6ca80ffef654965505981727b9fa06a51.
Дополнительная информация
Статус:
5.5 Medium
CVSS3
Связанные уязвимости
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
5.5 Medium
CVSS3