[Bug 1037007] New: VUL-1: CVE-2016-10351: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory
http://bugzilla.opensuse.org/show_bug.cgi?id=1037007 Bug ID: 1037007 Summary: VUL-1: CVE-2016-10351: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.2 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: mikhail.kasimov@gmail.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Ref: https://blogs.gentoo.org/ago/2017/05/01/telegram-desktop-insecure-permission... =================================================== Description: Telegram-desktop is the official desktop client for Telegram. During the navigation of my filesystem I found the .TelegramDesktop with 755 permission: drwxr-xr-x 4 ago ago 4096 nov 23 14:30 .TelegramDesktop Affected version: At least from 0.10.19 to 1.0.29 Fixed version: N/A Commit fix: N/A Credit: This bug was discovered by Agostino Sarubbo of Gentoo. CVE: CVE-2016-10351 Timeline: 2016-11-23: bug discovered and reported to upstream 2017-05-01: blog post about the issue 2017-05-01: CVE assigned Permalink: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory =================================================== (open-)SUSE: https://software.opensuse.org/package/telegram-desktop 1.0.24 (TW, server:messaging repo) 1.0.14 (42.2, server:messaging repo) 0.9.56 (42.1, server:messaging repo) -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1037007 Mikhail Kasimov <mikhail.kasimov@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Alias| |CVE-2016-10351 -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com