{"id":"USN-7198-1","summary":"rlottie vulnerabilities","details":"\nPaolo Giai discovered a series of stack-based overflow vulnerabilities in\nthe blit and gray_render_cubic functions of a custom fork of the rlottie\nlibrary. An attacker could possibly use this issue to leak sensitive \ninformation. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04\nLTS. (CVE-2021-31315, CVE-2021-31321)\n\nPaolo Giai discovered a series of type confusion vulnerabilities in the\nVDasher constructor and the LOTCompLayerItem::LOTCompLayerItem function\nof a custom fork of the rlottie library. An attacker could possibly use\nthis issue to leak sensitive information. This issue only affected Ubuntu\n20.04 LTS. (CVE-2021-31317, CVE-2021-31318)\n\nPaolo Giai discovered an integer overflow vulnerability in the \nLOTGradient::populate function of a custom fork of the rlottie library.\nAn attacker could possibly use this issue to leak sensitive information.\nThis issue only affected Ubuntu 20.04 LTS. (CVE-2021-31319)\n\nPaolo Giai discovered a series of heap buffer overflow vulnerabilities\nin the VGradientCache::generateGradientColorTable and\nLOTGradient::populate functions of a custom fork of the rlottie library.\nAn attacker could possibly use this issue to achieve remote code execution.\nThis issue only affected Ubuntu 20.04 LTS. (CVE-2021-31320, CVE-2021-31322)\n","modified":"2026-04-22T10:48:27.496604Z","published":"2025-01-10T01:11:01Z","related":["UBUNTU-CVE-2021-31315","UBUNTU-CVE-2021-31317","UBUNTU-CVE-2021-31318","UBUNTU-CVE-2021-31319","UBUNTU-CVE-2021-31320","UBUNTU-CVE-2021-31321","UBUNTU-CVE-2021-31322"],"upstream":["CVE-2021-31315","CVE-2021-31317","CVE-2021-31318","CVE-2021-31319","CVE-2021-31320","CVE-2021-31321","CVE-2021-31322","UBUNTU-CVE-2021-31315","UBUNTU-CVE-2021-31317","UBUNTU-CVE-2021-31318","UBUNTU-CVE-2021-31319","UBUNTU-CVE-2021-31320","UBUNTU-CVE-2021-31321","UBUNTU-CVE-2021-31322"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7198-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31315"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31317"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31318"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31319"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31320"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31321"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-31322"}],"affected":[{"package":{"name":"rlottie","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/rlottie@0~git20200305.a717479+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0~git20200305.a717479+dfsg-1ubuntu0.1~esm1"}]}],"versions":["0~git20190721.24346d0+dfsg-2","0~git20190721.24346d0+dfsg-2build1","0~git20200305.a717479+dfsg-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"librlottie0-1","binary_version":"0~git20200305.a717479+dfsg-1ubuntu0.1~esm1"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2021-31315","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31317","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31318","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31319","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31320","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31321","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31322","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7198-1.json"}},{"package":{"name":"rlottie","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/rlottie@0.1+dfsg-2ubuntu0.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1+dfsg-2ubuntu0.1"}]}],"versions":["0.1+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_name":"librlottie0-1","binary_version":"0.1+dfsg-2ubuntu0.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2021-31315","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-31321","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7198-1.json"}}],"schema_version":"1.7.5"}