Impact
All users of libsignal-service-rs
. Any contact may forge a sync message, impersonating another device of the local user. The origin of sync messages is not checked.
Patches
Patched libsignal-service can be found after commit 82d70f6. The Metadata
struct contains an additional was_encrypted
field, which breaks the API, but should be easily resolvable.
Workarounds
n.a.
References
n.a.
Impact
All users of
libsignal-service-rs
. Any contact may forge a sync message, impersonating another device of the local user. The origin of sync messages is not checked.Patches
Patched libsignal-service can be found after commit 82d70f6. The
Metadata
struct contains an additionalwas_encrypted
field, which breaks the API, but should be easily resolvable.Workarounds
n.a.
References
n.a.