Vulnerability Description
Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers an "index out of range" condition. NOTE: this issue is disputed by multiple third parties because the described attack scenario does not cross a privilege boundary
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Telegram | Telegram Desktop | 1.3.14 |
Related Weaknesses (CWE)
References
- https://www.openwall.com/lists/oss-security/2018/09/19/8ExploitMailing ListThird Party Advisory
- https://www.openwall.com/lists/oss-security/2018/09/19/8ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2018-17231?
CVE-2018-17231 is a vulnerability with a CVSS score of 7.5 (HIGH). Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers an "index out of ran...
How severe is CVE-2018-17231?
CVE-2018-17231 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17231?
Check the references section above for vendor advisories and patch information. Affected products include: Telegram Telegram Desktop.