PT-2019-4127 · Dino+1 · Dino+1

Published

2019-09-11

·

Updated

2020-09-14

·

CVE-2019-16237

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dino before 2019-09-10
Description The issue is related to insufficient input validation in the module/xep/0313 message archive management.vala module of the Dino instant messaging client. This could allow a remote attacker to impact data integrity.
Recommendations For versions before 2019-09-10, update to a version released after 2019-09-10 to resolve the issue. As a temporary workaround, consider restricting access to the module/xep/0313 message archive management.vala module to minimize the risk of exploitation.

Fix

Origin Validation Error

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04706
CVE-2019-16237
DSA-4524-1
USN-4306-1

Affected Products

Dino
Ubuntu