Remote Code Execution Vulnerability in Signal Private Messenger by Signal Foundation
CVE-2020-5753

5.3MEDIUM

Key Information:

Vendor

Signal

Vendor
CVE Published:
20 May 2020

What is CVE-2020-5753?

A vulnerability exists in Signal Private Messenger that allows a remote attacker to leverage improper handling of ICE Candidates prior to the victim answering or declining a call. This flaw may enable unauthorized disclosure of the DNS server currently in use, potentially exposing sensitive network details and increasing the risk of further attacks. Users of both Android and iOS versions of Signal are urged to update to secure versions promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Signal Private Messenger Android versions v4.59.0 and up, iOS versions v3.8.1.5 and up

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.