Описание
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
Ссылки
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
EPSS
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass t ...
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
EPSS
7.8 High
CVSS3
6.8 Medium
CVSS2