Bug#991493: telegram-desktop: CVE-2021-36769

2021-07-26 Thread Moritz Mühlenhoff
Am Mon, Jul 26, 2021 at 11:13:10PM +0300 schrieb Nicholas Guriev: > Hello! > > I skimmed the paper you pointed out and commit history in the upstream > Git repository, and I came to conclusion that to address the issue, it > is simpler and safer to upload the latest upstream release rather than >

Bug#991493: telegram-desktop: CVE-2021-36769

2021-07-26 Thread Nicholas Guriev
Hello! I skimmed the paper you pointed out and commit history in the upstream Git repository, and I came to conclusion that to address the issue, it is simpler and safer to upload the latest upstream release rather than collecting and backporting targeted fixes despite of the final stage of

Bug#991493: telegram-desktop: CVE-2021-36769

2021-07-25 Thread Moritz Mühlenhoff
Source: telegram-desktop X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for telegram-desktop. CVE-2021-36769[0]: | A reordering issue exists in Telegram before 7.8.1 for Android, | Telegram before 7.8.3 for iOS, and