An insufficient session expiration has been reported in Telegram.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Telegram: Security bypass Date: May 26, 2021 Bugs: #771684 ID: 202105-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An insufficient session expiration has been reported in Telegram. Background ========= Telegram is a cloud-based mobile and desktop messaging app with a focus on security and speed. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-im/telegram-desktop < 2.4.11 > = 2.4.11 2 net-im/telegram-desktop-bin < 2.4.11 > = 2.4.11 ------------------------------------------------------------------- 2 affected packages Description ========== It was discovered that Telegram failed to invalidate a recently active session. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Telegram users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-im/telegram-desktop-2.4.11" All Telegram binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =net-im/telegram-desktop-bin-2.4.11" References ========= [ 1 ] CVE-2021-27351 https://nvd.nist.gov/vuln/detail/CVE-2021-27351 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.