PT-2018-14191 · Telegram+1 · Telegram Desktop+2

Dhiraj

·

Publicado

2018-09-29

·

Atualizado

2023-08-08

·

CVE-2018-17780

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telegram Desktop (aka tdesktop) version 1.3.14 Telegram version 3.3.0.0 WP8.1 on Windows
Description The issue allows the leakage of end-user public and private IP addresses during a call due to an unsafe default behavior. This behavior involves accepting P2P connections from clients outside of the My Contacts list. The leakage occurs when a Telegram call is made and both parties use the peer-to-peer option.
Recommendations For Telegram Desktop version 1.3.14, consider disabling the peer-to-peer call feature until a patch is available. For Telegram version 3.3.0.0 WP8.1 on Windows, restrict the acceptance of P2P connections to only trusted contacts to minimize the risk of IP address leakage.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2831
CVE-2018-17780

Produtos afetados

Alt Linux
Telegram
Telegram Desktop