Impact
All users of libsignal-service-rs. Any contact may forge a sync message, impersonating another device of the local user. The origin of sync messages is not checked.
Patches
Patched libsignal-service can be found after commit 82d70f6. The Metadata struct contains an additional was_encrypted field, which breaks the API, but should be easily resolvable.
Workarounds
n.a.
References
n.a.
Impact
All users of
libsignal-service-rs. Any contact may forge a sync message, impersonating another device of the local user. The origin of sync messages is not checked.Patches
Patched libsignal-service can be found after commit 82d70f6. The
Metadatastruct contains an additionalwas_encryptedfield, which breaks the API, but should be easily resolvable.Workarounds
n.a.
References
n.a.