PT-2020-6163 · Telegram+1 · Telegram Ios+4

Polict

·

Published

2020-09-30

·

Updated

2021-05-25

·

CVE-2021-31323

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telegram Messenger versions prior to 7.1.0 Telegram Android versions prior to 7.1.0 (2090) Telegram iOS versions prior to 7.1 Telegram macOS versions prior to 7.1
Description The issue is caused by a heap buffer overflow in the LottieParserImpl::parseDashProperty function. This can allow a remote attacker to disclose protected information by using a malicious animated sticker, potentially accessing heap memory out-of-bounds on a victim device.
Recommendations For Telegram Messenger versions prior to 7.1.0, update to version 7.1.0 or later. For Telegram Android versions prior to 7.1.0 (2090), update to version 7.1.0 or later. For Telegram iOS versions prior to 7.1, update to version 7.1 or later. For Telegram macOS versions prior to 7.1, update to version 7.1 or later. As a temporary workaround, consider avoiding the use of animated stickers from untrusted sources until the issue is resolved.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03325
CVE-2021-31323

Affected Products

Lottieparserimpl
Telegram Android
Telegram Messenger
Telegram Ios
Telegram Macos