PT-2020-6163 · Telegram+1 · Telegram Ios+4
Polict
·
Published
2020-09-30
·
Updated
2021-05-25
·
CVE-2021-31323
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Telegram Messenger versions prior to 7.1.0
Telegram Android versions prior to 7.1.0 (2090)
Telegram iOS versions prior to 7.1
Telegram macOS versions prior to 7.1
Description
The issue is caused by a heap buffer overflow in the LottieParserImpl::parseDashProperty function. This can allow a remote attacker to disclose protected information by using a malicious animated sticker, potentially accessing heap memory out-of-bounds on a victim device.
Recommendations
For Telegram Messenger versions prior to 7.1.0, update to version 7.1.0 or later.
For Telegram Android versions prior to 7.1.0 (2090), update to version 7.1.0 or later.
For Telegram iOS versions prior to 7.1, update to version 7.1 or later.
For Telegram macOS versions prior to 7.1, update to version 7.1 or later.
As a temporary workaround, consider avoiding the use of animated stickers from untrusted sources until the issue is resolved.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lottieparserimpl
Telegram Android
Telegram Messenger
Telegram Ios
Telegram Macos