CVE-2020-5753: Medium severity Signal Private Messenger Android vulnerability
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5753?
CVE-2020-5753 is a vulnerability found in Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up that allows a remote non-contact to ring a victim's Signal phone and disclose the currently used DNS server.
Which versions of Signal Private Messenger are affected by CVE-2020-5753?
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up are affected by CVE-2020-5753.
How severe is CVE-2020-5753?
CVE-2020-5753 has a severity rating of 5.3 (Medium).
How can the vulnerability in CVE-2020-5753 be exploited?
The vulnerability in CVE-2020-5753 can be exploited by a remote non-contact to ring a victim's Signal phone and disclose the currently used DNS server.
Is there a fix available for CVE-2020-5753?
Currently, there is no known fix for CVE-2020-5753. It is recommended to follow the advice provided by the software vendor or security advisories.