605
VMScore

CVE-2019-10044

Published: 25/03/2019 Updated: 21/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Telegram Desktop prior to 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

telegram telegram

telegram telegram_desktop

Vendor Advisories

Debian Bug report logs - #927711 CVE-2019-10044 Package: telegram-desktop; Maintainer for telegram-desktop is Nicholas Guriev <guriev-ns@yaru>; Source for telegram-desktop is src:telegram-desktop (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 21 Apr 2019 20:21:02 UTC Severity: imp ...