PT-2018-14191 · Telegram+1 · Telegram Desktop+2
Dhiraj
·
Publicado
2018-09-29
·
Atualizado
2023-08-08
·
CVE-2018-17780
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Telegram Desktop (aka tdesktop) version 1.3.14
Telegram version 3.3.0.0 WP8.1 on Windows
Description
The issue allows the leakage of end-user public and private IP addresses during a call due to an unsafe default behavior. This behavior involves accepting P2P connections from clients outside of the My Contacts list. The leakage occurs when a Telegram call is made and both parties use the peer-to-peer option.
Recommendations
For Telegram Desktop version 1.3.14, consider disabling the peer-to-peer call feature until a patch is available.
For Telegram version 3.3.0.0 WP8.1 on Windows, restrict the acceptance of P2P connections to only trusted contacts to minimize the risk of IP address leakage.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Telegram
Telegram Desktop