Spoofing attack in Dino - CVE-2023-28686

 

Spoofing attack in Dino - CVE-2023-28686

Published: March 30, 2023


Vulnerability identifier: #VU74214
CSH Severity: Medium
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28686
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can send a specially crafted message to the victim and modify their personal bookmark store, which can lead the victim into joining an untrusted group chat.


Affected software

Dino
Debian Linux
Ubuntu
Fedora
dino-im (Ubuntu package)
dino-im (Debian package)
dino

How to mitigate CVE-2023-28686

Install updates from vendor's website.

Dino - addressed in versions 0.2.3, 0.3.2, 0.4.2
dino-im (Ubuntu package) - update to Ubuntu Pro
dino-im (Debian package) - update to 0.2.0-3+deb11u1
dino - addressed in versions 0.3.2-1.fc36, 0.3.2-1.fc37, 0.4.2-1.fc38

External References

Related Security Bulletins