CVE-2021-31319: Integer Overflow
Last updated 24 July 2024
Other sources
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31319?
CVE-2021-31319 is a vulnerability that affects Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1.
What is the severity of CVE-2021-31319?
The severity of CVE-2021-31319 is medium with a severity value of 5.5.
How does CVE-2021-31319 affect Telegram?
CVE-2021-31319 affects Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 by causing an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library.
What is the risk of CVE-2021-31319?
The risk of CVE-2021-31319 is that a remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animation file.
How can I fix CVE-2021-31319?
To fix CVE-2021-31319, users should update their Telegram Android, iOS, or macOS to versions 7.1.0 or later.