CVE Vulnerabilities

CVE-2020-12474

Published: May 01, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.

Affected Software

NameVendorStart VersionEnd Version
TelegramTelegram*6.0.1 (including)
Telegram_desktopTelegram*2.0.1 (including)
Telegram-desktopUbuntubionic*
Telegram-desktopUbuntueoan*
Telegram-desktopUbuntufocal*
Telegram-desktopUbuntutrusty*

References