CVE-2018-17613: Critical severity telegram vulnerability
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17613?
CVE-2018-17613 is a vulnerability in Telegram Desktop version 1.3.16 alpha that allows the transmission of credentials and application data in cleartext when the "Use proxy" feature is enabled.
How severe is CVE-2018-17613?
CVE-2018-17613 has a severity rating of 9.8, which is classified as critical.
How does CVE-2018-17613 affect Telegram Desktop?
CVE-2018-17613 affects Telegram Desktop version 1.3.16 alpha when the "Use proxy" feature is enabled.
How can I fix CVE-2018-17613?
To fix CVE-2018-17613, update Telegram Desktop to a version that has patched the vulnerability.
Where can I find more information about CVE-2018-17613?
More information about CVE-2018-17613 can be found at the following references: [Reference 1](https://seclists.org/oss-sec/2018/q3/280), [Reference 2](https://www.inputzero.io/2018/09/telegram-share-password-in-cleartext.html).