ricochet -- information disclosure

Affected packages
ricochet < 1.1.2


VuXML ID d71831ef-e6f8-11e5-85be-14dae9d210b8
Discovery 2016-02-15
Entry 2016-03-10

By sending a nickname with some HTML tags in a contact request, an attacker could cause Ricochet to make network requests without Tor after the request is accepted, which would reveal the user's IP address.