Hi,

09.05.2019 23:42, Moritz Mühlenhoff пишет:
> What's the status? Has upstream been contacted for an isolated fix, are
> you planning to address this for buster?


As John Preston said, there was no a special fix of the issue in 1.5.12.
It is mistake that this version is considered to contain the fix.
And as far as I can see, Telegram Desktop has no a fix of this CVE yet.

At least some code[1] in HistoryWebPage checks for hidden URLs. But it
does not always work properly. For example, it shows a confirmation
for https://www.аррӏе.com/ (https://www.xn--80ak6aa92e.com/) but not
for http://blаzeinfosec.com (http://xn--blzeinfosec-zij.com).

 [1]: 
https://sources.debian.org/src/telegram-desktop/1.5.11-1/Telegram/SourceFiles/history/media/history_media_web_page.cpp/#L133

Reply via email to