CVE-2021-31317: Medium severity allegro vulnerability
Last updated 24 July 2024
Other sources
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Telegram issue?
The vulnerability ID for this Telegram issue is CVE-2021-31317.
What is the affected software?
The affected software includes Telegram Android versions before 7.1.0 (2090), Telegram iOS versions before 7.1, and Telegram macOS versions before 7.1.
What is the severity level of CVE-2021-31317?
The severity level of CVE-2021-31317 is medium with a severity value of 5.5.
What is the vulnerability description?
Telegram Android, iOS, and macOS versions before 7.1 are affected by a Type Confusion vulnerability in the VDasher constructor of their custom fork of the rlottie library.
How can a remote attacker exploit this vulnerability?
A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animation.