Description
Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interface to trigger an application crash.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
Aryan Chehreghani
References
www.exploit-db.com/exploits/50247
www.exploit-db.com/exploits/50247 (ExploitDB-50247)
telegram.org (Official Telegram Homepage)
www.vulncheck.com/.../telegram-desktop-denial-of-service-poc (VulnCheck Advisory: Telegram Desktop 2.9.2 - Denial of Service (PoC))