Impact
Samsung Opensource rLottie contains a stack-based buffer overflow in its vector animation rendering routine. The vulnerability is triggered by processing a crafted animation file, leading to a local buffer overflow that corrupts adjacent memory. The CVE description does not confirm that execution of arbitrary code is possible, only that memory corruption can occur.
Affected Systems
The defect affects the rLottie library at the Git commit 480a2ad0c5d2e45458c545b8213279e9e8b71e39. No other vendors, products, or versions are listed in the CVE entry.
Risk and Exploitability
The CVSS score of 4.4 indicates a low overall severity, and the EPSS score of less than 1% shows an extremely low likelihood of known exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the delivery of a malicious animation file to an application that renders rLottie animations. This inference assumes the attacker can supply an untrusted animation. Successful exploitation could corrupt memory and potentially destabilize the rendering process.
OpenCVE Enrichment