CVE Vulnerabilities

CVE-2020-5753

Always-Incorrect Control Flow Implementation

Published: May 20, 2020 | Modified: Apr 07, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victims Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.

Weakness

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

Affected Software

Name Vendor Start Version End Version
Private_messenger Signal * 4.59.0 (including)
Signal Signal * 3.8.1.5 (including)

References