Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-9527 Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T10:54:10.574Z

Reserved: 2018-09-29T00:00:00

Link: CVE-2018-17780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-29T19:29:00.237

Modified: 2024-11-21T03:54:57.610

Link: CVE-2018-17780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.