Bugzilla – Bug 1037007
[server:messaging/telegram-desktop]: CVE-2016-10351: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory
Last modified: 2017-12-11 01:11:37 UTC
Ref: https://blogs.gentoo.org/ago/2017/05/01/telegram-desktop-insecure-permission-of-home-telegramdesktop-directory/ =================================================== Description: Telegram-desktop is the official desktop client for Telegram. During the navigation of my filesystem I found the .TelegramDesktop with 755 permission: drwxr-xr-x 4 ago ago 4096 nov 23 14:30 .TelegramDesktop Affected version: At least from 0.10.19 to 1.0.29 Fixed version: N/A Commit fix: N/A Credit: This bug was discovered by Agostino Sarubbo of Gentoo. CVE: CVE-2016-10351 Timeline: 2016-11-23: bug discovered and reported to upstream 2017-05-01: blog post about the issue 2017-05-01: CVE assigned Permalink: telegram-desktop: insecure permission of $HOME/.TelegramDesktop directory =================================================== (open-)SUSE: https://software.opensuse.org/package/telegram-desktop 1.0.24 (TW, server:messaging repo) 1.0.14 (42.2, server:messaging repo) 0.9.56 (42.1, server:messaging repo)
Progress: bug reported to upstream. Here is the related github issue: https://github.com/telegramdesktop/tdesktop/issues/2666 Waiting for upstream to fix it.
Update: upstream has fixed the bug by setting the permission to 700. For details, see: https://github.com/telegramdesktop/tdesktop/issues/2666 as well as https://github.com/telegramdesktop/tdesktop/pull/3842 This bug will be closed when the fix is merged to the next release and I will update the packaging in the server:messaging repository.
Telegram Desktop in server:messaging repository has been upgraded to 1.1.29. Bug fixed by upstream.