PT-2023-21905 · Dino+2 · Dino+2

Kim Alvefur

·

Published

2023-03-24

·

Updated

2025-04-09

·

CVE-2023-28686

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dino versions prior to 0.2.3 Dino versions 0.3.x prior to 0.3.2 Dino versions 0.4.x prior to 0.4.2
Description The issue allows attackers to modify the personal bookmark store via a crafted message. This can lead to changing the display of group chats or forcing a victim to join a group chat, potentially tricking the victim into disclosing sensitive information. When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update, or remove entries in the user’s personal bookmark store without requiring further user interaction.
Recommendations For versions prior to 0.2.3, update to version 0.2.3 or later. For versions 0.3.x prior to 0.3.2, update to version 0.3.2 or later. For versions 0.4.x prior to 0.4.2, update to version 0.4.2 or later. As a temporary workaround, consider restricting the handling of crafted messages until a patch is applied.

Fix

IDOR

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1504
CVE-2023-28686
DSA-5379-1
MGASA-2023-0122
OPENSUSE-SU-2024:12813-1
USN-7430-1

Affected Products

Dino
Linuxmint
Ubuntu