<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p><span class="im">==============================<wbr>==============================<wbr>==============<br>
        Ubuntu Security Notice USN-7198-1<br>
        January 10, 2025<br>
        <br>
        rlottie vulnerabilities<br>
        ==============================<wbr>==============================<wbr>==============<br>
        <br>
        A security issue affects these releases of Ubuntu and its
        derivatives:<br>
        <br>
        - Ubuntu 22.04 LTS<br>
        - Ubuntu 20.04 LTS<br>
        <br>
        Summary:<br>
        <br>
        Several security issues were fixed in rlottie.<br>
        <br>
        Software Description:<br>
        - rlottie: library for rendering vector based animations and art<br>
        <br>
        Details:<br>
        <br>
        Paolo Giai discovered a series of stack-based overflow
        vulnerabilities in<br>
        the blit and gray_render_cubic functions of a custom fork of the
        rlottie<br>
      </span>
      library. An attacker could possibly use this issue to leak
      sensitive <br>
      information. This issue only affected Ubuntu 20.04 LTS and Ubuntu
      22.04<span class="im"><br>
        LTS. (CVE-2021-31315, CVE-2021-31321)<br>
        <br>
        Paolo Giai discovered a series of type confusion vulnerabilities
        in the<br>
        VDasher constructor and the <a class="moz-txt-link-freetext" href="LOTCompLayerItem::LOTCompLayer">LOTCompLayerItem::LOTCompLayer</a><wbr>Item
        function<br>
        of a custom fork of the rlottie library. An attacker could
        possibly use<br>
      </span>
      this issue to leak sensitive information. This issue only affected
      Ubuntu<span class="im"><br>
        20.04 LTS. (CVE-2021-31317, CVE-2021-31318)<br>
        <br>
        Paolo Giai discovered an integer overflow vulnerability in the <br>
        <a class="moz-txt-link-freetext" href="LOTGradient::populate">LOTGradient::populate</a> function of a custom fork of the rlottie
        library.<br>
      </span>
      An attacker could possibly use this issue to leak sensitive
      information.<span class="im"><br>
        This issue only affected Ubuntu 20.04 LTS. (CVE-2021-31319)<br>
        <br>
        Paolo Giai discovered a series of heap buffer overflow
        vulnerabilities<br>
        in the <a class="moz-txt-link-freetext" href="VGradientCache::generateGradie">VGradientCache::generateGradie</a><wbr>ntColorTable and<br>
        <a class="moz-txt-link-freetext" href="LOTGradient::populate">LOTGradient::populate</a> functions of a custom fork of the rlottie
        library.</span></p>
  </body>
</html>