Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-31317

Опубликовано: 18 мая 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.5

Описание

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

0.1+dfsg-4.2
esm-apps/focal

released

0~git20200305.a717479+dfsg-1ubuntu0.1~esm1
esm-apps/jammy

not-affected

0.1+dfsg-2ubuntu0.1
esm-apps/noble

not-affected

0.1+dfsg-4ubuntu1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 4 лет назад

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVSS3: 5.5
debian
больше 4 лет назад

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS ...

github
больше 3 лет назад

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость конструктора VDasher библиотеки для воспроизведения Lottie анимаций Rlottie, связанная с ошибками преобразования типов данных, позволяющая нарушителю получить доступ к конфиденциальным данным

4.3 Medium

CVSS2

5.5 Medium

CVSS3