Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9970

Опубликовано: 24 мар. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:signal:private_messenger:*:*:*:*:*:android:*:*
Версия до 4.35.3 (включая)
cpe:2.3:a:signal:signal-desktop:*:*:*:*:*:*:*:*
Версия до 1.23.1 (включая)

EPSS

Процентиль: 62%
0.00423
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
debian
почти 7 лет назад

Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal ...

CVSS3: 6.5
github
больше 3 лет назад

Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.

EPSS

Процентиль: 62%
0.00423
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo