CVE-2020-5753

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/05/2020
Last modified:
07/04/2022

Description

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:signal:private_messenger:*:*:*:*:*:android:*:* 4.59.0 (including)
cpe:2.3:a:signal:signal:*:*:*:*:*:iphone_os:*:* 3.8.1.5 (including)


References to Advisories, Solutions, and Tools