Impact
All users of libsignal-service-rs
are impacted. Plaintext content envelopes can be injected by a server or a malicious client, and may bypass the end-to-end encryption and authentication.
Patches
The vulnerability is fixed per 82d70f6. The Metadata
struct contains an additional was_encrypted
field, which breaks the API, but should be easily resolvable.
Workarounds
Not known.
References
n.a.
Impact
All users of
libsignal-service-rs
are impacted. Plaintext content envelopes can be injected by a server or a malicious client, and may bypass the end-to-end encryption and authentication.Patches
The vulnerability is fixed per 82d70f6. The
Metadata
struct contains an additionalwas_encrypted
field, which breaks the API, but should be easily resolvable.Workarounds
Not known.
References
n.a.