PT-2018-14191 · Telegram+1 · Telegram Desktop+2

Dhiraj

·

Published

2018-09-29

·

Updated

2023-08-08

·

CVE-2018-17780

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telegram Desktop (aka tdesktop) version 1.3.14 Telegram version 3.3.0.0 WP8.1 on Windows
Description The issue allows the leakage of end-user public and private IP addresses during a call due to an unsafe default behavior. This behavior involves accepting P2P connections from clients outside of the My Contacts list. The leakage occurs when a Telegram call is made and both parties use the peer-to-peer option.
Recommendations For Telegram Desktop version 1.3.14, consider disabling the peer-to-peer call feature until a patch is available. For Telegram version 3.3.0.0 WP8.1 on Windows, restrict the acceptance of P2P connections to only trusted contacts to minimize the risk of IP address leakage.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2831
CVE-2018-17780

Affected Products

Alt Linux
Telegram
Telegram Desktop