Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqgm-mqmr-px3p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.

EPSS

Процентиль: 46%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-670

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.

EPSS

Процентиль: 46%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-670