CVE-2021-31323: Buffer Overflow
Published May 18, 2021
·Updated
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
Affected Software
3 affected components
Telegram Telegram Android<7.1.0
Telegram Telegram Iphone Os<7.1.0
Telegram Telegram macOS<7.1.0
Event History
May 18, 2021
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-31323.
2
What is the severity level of CVE-2021-31323?
The severity level of CVE-2021-31323 is medium (5.5).
3
Which software versions are affected by CVE-2021-31323?
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by CVE-2021-31323.
4
What is the CWE number associated with CVE-2021-31323?
The CWE number associated with CVE-2021-31323 is CWE-119 and CWE-787.
5
How can I fix the vulnerability CVE-2021-31323?
To fix the vulnerability CVE-2021-31323, update Telegram Android, Telegram iOS, and Telegram macOS to version 7.1.0 or higher.