Multiple vulnerabilities have been found in Telegram, the worst of which could result in information disclosure.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Telegram Desktop: Multiple vulnerabilities Date: January 27, 2021 Bugs: #736774, #749288 ID: 202101-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Telegram, the worst of which could result in information disclosure. Background ========= Telegram is a messaging app with a focus on speed and security. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-im/telegram-desktop < 2.4.4 > = 2.4.4 Description ========== Multiple vulnerabilities have been discovered in Telegram Desktop. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Telegram Desktop users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-im/telegram-desktop-2.4.4" References ========= [ 1 ] CVE-2020-17448 https://nvd.nist.gov/vuln/detail/CVE-2020-17448 [ 2 ] CVE-2020-25824 https://nvd.nist.gov/vuln/detail/CVE-2020-25824 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-34 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for groovy ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2367-1 Rating: moderate References: #1179729 Cross-References: CVE-2020-17521 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for groovy fixes the following issues: - groovy was updated to 2.4.21 - CVE-2020-17521: Fixed an information disclosure vulnerability (bsc#1179729). This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-2367=1 Package List: - openSUSE Leap 15.2 (noarch): groovy-2.4.21-lp152.2.3.2 groovy-ant-2.4.21-lp152.2.3.2 groovy-bsf-2.4.21-lp152.2.3.2 groovy-console-2.4.21-lp152.2.3.2 groovy-docgenerator-2.4.21-lp152.2.3.2 groovy-groovydoc-2.4.21-lp152.2.3.2 groovy-groovysh-2.4.21-lp152.2.3.2 groovy-jmx-2.4.21-lp152.2.3.2 groovy-json-2.4.21-lp152.2.3.2 groovy-jsr223-2.4.21-lp152.2.3.2 groovy-lib-2.4.21-lp152.2.3.2 groovy-nio-2.4.21-lp152.2.3.2 groovy-servlet-2.4.21-lp152.2.3.2 groovy-sql-2.4.21-lp152.2.3.2 groovy-swing-2.4.21-lp152.2.3.2 groovy-templates-2.4.21-lp152.2.3.2 groovy-test-2.4.21-lp152.2.3.2 groovy-testng-2.4.21-lp152.2.3.2 groovy-xml-2.4.21-lp152.2.3.2 References: https://www.suse.com/security/cve/CVE-2020-17521.html https://bugzilla.suse.com/1179729 . A fresh patch has been released for openSUSE addressinga security vulnerability related to information exposure in Groovy, classified as moderate.. openSUSE Security Update,Groovy Update,Information Disclosure,Software Patch,Linux Updates. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.