First published: Mon May 01 2017(Updated: )
Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telegram | =0.10.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10351 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
Telegram Desktop version 0.10.19 is the specific version affected by CVE-2016-10351.
To fix CVE-2016-10351, change the permissions of the $HOME/.TelegramDesktop directory to restrict access.
CVE-2016-10351 allows local users to access sensitive authentication information stored by Telegram Desktop.
No, CVE-2016-10351 is not a remote vulnerability; it requires local access to the machine to exploit.