Impact
An integer overflow flaw in the Samsung rlottie library can cause a buffer overflow, leading to potential memory corruption and remote code execution if an attacker can supply malicious animation data. The description does not specify the exact exploitation scenario, but the presence of a buffer overflow suggests that corrupted memory could be leveraged to alter program flow.
Affected Systems
Samsung’s open‑source rlottie animation rendering library. Any software incorporating this library, particularly those that accept external animation files, is potentially impacted. The vendor list is limited to the rlottie project; no specific versions are supplied in the data.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, while the EPSS score of less than 1 percent indicates a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or contextual: an attacker would need to deliver crafted animation data to a process that loads rlottie. Without further detail, it is inferred that exploitation would require either a privileged or user‑controlled context within the application using the library.
OpenCVE Enrichment