Security Advisory

CVE-2017-17715

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-12-16 19:00:00
Last updated 2024-08-05 20:59:17
Assigner mitre
State PUBLISHED

Description

The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a remote peer, as demonstrated by writing to tgnet.dat or tgnet.dat.bak.