Bug ID | 1037007 |
---|---|
Summary | VUL-1: CVE-2016-10351: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 42.2 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Security |
Assignee | security-team@suse.de |
Reporter | mikhail.kasimov@gmail.com |
QA Contact | qa-bugs@suse.de |
Found By | --- |
Blocker | --- |
Ref: https://blogs.gentoo.org/ago/2017/05/01/telegram-desktop-insecure-permission-of-home-telegramdesktop-directory/ =================================================== Description: Telegram-desktop is the official desktop client for Telegram. During the navigation of my filesystem I found the .TelegramDesktop with 755 permission: drwxr-xr-x 4 ago ago 4096 nov 23 14:30 .TelegramDesktop Affected version: At least from 0.10.19 to 1.0.29 Fixed version: N/A Commit fix: N/A Credit: This bug was discovered by Agostino Sarubbo of Gentoo. CVE: CVE-2016-10351 Timeline: 2016-11-23: bug discovered and reported to upstream 2017-05-01: blog post about the issue 2017-05-01: CVE assigned Permalink: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory =================================================== (open-)SUSE: https://software.opensuse.org/package/telegram-desktop 1.0.24 (TW, server:messaging repo) 1.0.14 (42.2, server:messaging repo) 0.9.56 (42.1, server:messaging repo)