CVE-2023-5217

  • Cybersecurity
  • Sovereign solutions
  • Defence
  • Type Cyber Threat Research

Publication date : 30/10/2023
State : public

Codec VP8 Buffer overflow

Description: 

The desktop client is based on Electron based on Chromium. And Chromium versions prior to version 117.0.5938.132 with libvpx prior to 1.13.1 are vulnerable to out of bounds memory via shared crafted Video or potentially inline crafted Conferences. The Android app based on libvpx prior to 1.13.1 is vulnerable to out of bounds memory via shared crafted Video or potentially inline crafted Conferences. The Ios app based on libvpx prior to 1.13.1 is potentially vulnerable to out of bounds memory via inline crafted Conferences.


Affected versions:

Windows and Macosx Citadel desktop clients 7.8.1 and lower IOS app 7.8.1 and lower
Android 7.8.1 App and lower.

Remediation: 

  • Update the Citadel destop to version 10/02/2023-7.8.2 or higher; if not automatically lauched - the update can be launched from the update menu.
  • Update the Citadel Android App tà 10/05/2023-7.8.2 version or higher.
  • Update the Citadel Ios App to 10/24/2023-7.9 version or higher.