Impact
The vulnerability arises from improper validation of a quantity field in input data. An attacker can supply malformed or out‑of‑range values that are accepted by rlottie, leading to manipulation of the processed data. This flaw can alter visual representations or cause incorrect rendering, potentially affecting application stability or leading to erroneous output. The weakness is classified as CWE‑1284.
Affected Systems
The issue exists in the Samsung Open Source rlottie project. No specific version range is provided, so any release that has not yet incorporated the recent pull request that addresses the validation logic is considered vulnerable. Check the vendor repository for the latest commit or tagged release.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity. Because the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain. The flaw is presumed local or requires the ability to supply input to rlottie, meaning that an attacker would need to control the data being fed into the library. Nonetheless, the integrity of rendered output can be compromised, justifying timely remediation.
OpenCVE Enrichment