Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.
References
Link | Resource |
---|---|
https://github.com/telegramdesktop/tdesktop/issues/2666 | Issue Tracking Patch Third Party Advisory |
https://github.com/telegramdesktop/tdesktop/pull/3842/commits/388703b9ca1912a5438e37f9dd54c35805f2c594 | |
https://github.com/telegramdesktop/tdesktop/issues/2666 | Issue Tracking Patch Third Party Advisory |
https://github.com/telegramdesktop/tdesktop/pull/3842/commits/388703b9ca1912a5438e37f9dd54c35805f2c594 |
Configurations
History
21 Nov 2024, 02:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/telegramdesktop/tdesktop/issues/2666 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/telegramdesktop/tdesktop/pull/3842/commits/388703b9ca1912a5438e37f9dd54c35805f2c594 - |
Information
Published : 2017-05-01 01:59
Updated : 2024-11-21 02:43
NVD link : CVE-2016-10351
Mitre link : CVE-2016-10351
CVE.ORG link : CVE-2016-10351
JSON object : View
Products Affected
telegram_desktop
- telegram_desktop
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor