CVE-2023-28686
Summary
| CVE | CVE-2023-28686 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-24 04:15:00 UTC |
| Updated | 2023-11-07 04:10:00 UTC |
| Description | Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: dino-0.3.2-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5379-1 dino-im |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 38 Update: dino-0.4.2-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: dino-0.3.2-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: dino-0.3.2-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Insufficient message sender validation in Dino - Dino. Communicating happiness. |
CONFIRM |
dino.im |
|
| [SECURITY] Fedora 37 Update: dino-0.3.2-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: dino-0.4.2-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181666 Debian Security Update for dino-im (DSA 5379-1)
- 183537 Debian Security Update for dino-im (CVE-2023-28686)
- 283842 Fedora Security Update for dino (FEDORA-2023-587d6a00c3)
- 283843 Fedora Security Update for dino (FEDORA-2023-f003d8e633)
- 284224 Fedora Security Update for dino (FEDORA-2023-ea6b94395f)
- 502693 Alpine Linux Security Update for dino
- 503155 Alpine Linux Security Update for dino
- 504664 Alpine Linux Security Update for dino
- 505998 Alpine Linux Security Update for dino
- 691097 Free Berkeley Software Distribution (FreeBSD) Security Update for dino (dec6b8e9-c9fe-11ed-bb39-901b0e9408dc)