Vulnerability Description
Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Telegram Desktop | Telegram Desktop | 0.10.19 |
Related Weaknesses (CWE)
References
- https://github.com/telegramdesktop/tdesktop/issues/2666Issue TrackingPatchThird Party Advisory
- https://github.com/telegramdesktop/tdesktop/pull/3842/commits/388703b9ca1912a543
- https://github.com/telegramdesktop/tdesktop/issues/2666Issue TrackingPatchThird Party Advisory
- https://github.com/telegramdesktop/tdesktop/pull/3842/commits/388703b9ca1912a543
FAQ
What is CVE-2016-10351?
CVE-2016-10351 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.
How severe is CVE-2016-10351?
CVE-2016-10351 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10351?
Check the references section above for vendor advisories and patch information. Affected products include: Telegram Desktop Telegram Desktop.