From 88fa6da593ecf70fc090af04d40eb08c4a9ba653 Mon Sep 17 00:00:00 2001 From: Thomas Deutschmann Date: Wed, 26 May 2021 10:17:53 +0200 Subject: [ GLSA 202105-07 ] Telegram: Security bypass Signed-off-by: Thomas Deutschmann --- glsa-202105-07.xml | 59 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 glsa-202105-07.xml (limited to 'glsa-202105-07.xml') diff --git a/glsa-202105-07.xml b/glsa-202105-07.xml new file mode 100644 index 00000000..500983db --- /dev/null +++ b/glsa-202105-07.xml @@ -0,0 +1,59 @@ + + + + Telegram: Security bypass + An insufficient session expiration has been reported in Telegram. + telegram + 2021-05-26 + 2021-05-26 + 771684 + remote + + + 2.4.11 + 2.4.11 + + + 2.4.11 + 2.4.11 + + + +

Telegram is a cloud-based mobile and desktop messaging app with a focus + on security and speed. +

+
+ +

It was discovered that Telegram failed to invalidate a recently active + session. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Telegram users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-im/telegram-desktop-2.4.11" + + +

All Telegram binary users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose + ">=net-im/telegram-desktop-bin-2.4.11" + + +
+ + CVE-2021-27351 + + whissi + whissi +
-- cgit v1.2.3-65-gdbad