PT-2023-21905 · Dino+2 · Dino+2
Kim Alvefur
·
Published
2023-03-24
·
Updated
2025-04-09
·
CVE-2023-28686
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dino versions prior to 0.2.3
Dino versions 0.3.x prior to 0.3.2
Dino versions 0.4.x prior to 0.4.2
Description
The issue allows attackers to modify the personal bookmark store via a crafted message. This can lead to changing the display of group chats or forcing a victim to join a group chat, potentially tricking the victim into disclosing sensitive information. When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update, or remove entries in the user’s personal bookmark store without requiring further user interaction.
Recommendations
For versions prior to 0.2.3, update to version 0.2.3 or later.
For versions 0.3.x prior to 0.3.2, update to version 0.3.2 or later.
For versions 0.4.x prior to 0.4.2, update to version 0.4.2 or later.
As a temporary workaround, consider restricting the handling of crafted messages until a patch is applied.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dino
Linuxmint
Ubuntu