Telegram: Security bypass — GLSA 202105-07

An insufficient session expiration has been reported in Telegram.

Affected packages

net-im/telegram-desktop on all architectures
Affected versions < 2.4.11
Unaffected versions >= 2.4.11
net-im/telegram-desktop-bin on all architectures
Affected versions < 2.4.11
Unaffected versions >= 2.4.11

Background

Telegram is a cloud-based mobile and desktop messaging app with a focus on security and speed.

Description

It was discovered that Telegram failed to invalidate a recently active session.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Resolution

All Telegram users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-im/telegram-desktop-2.4.11"
 

All Telegram binary users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose
 ">=net-im/telegram-desktop-bin-2.4.11"
 

References

Release date
May 26, 2021

Latest revision
May 26, 2021: 1

Severity
low

Exploitable
remote

Bugzilla entries