Описание
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | 0.1+dfsg-4.2 |
| esm-apps/focal | not-affected | 0~git20200305.a717479+dfsg-1ubuntu0.1~esm1 |
| esm-apps/jammy | not-affected | 0.1+dfsg-2ubuntu0.1 |
| esm-apps/noble | not-affected | 0.1+dfsg-4ubuntu1 |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | 0~git20200305.a717479+dfsg-1 |
| groovy | ignored | end of life |
| hirsute | ignored | end of life |
| impish | ignored | end of life |
Показывать по
4.3 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS ...
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
Уязвимость функции LottieParserImpl::parseDashProperty программы мгновенного обмена сообщениями Telegram Messenger, позволяющая нарушителю раскрыть защищаемую информацию
4.3 Medium
CVSS2
5.5 Medium
CVSS3