Spoofing attack in Dino - CVE-2023-28686
Published: March 30, 2023
Vulnerability identifier: #VU74214
CSH Severity: Medium
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28686
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can send a specially crafted message to the victim and modify their personal bookmark store, which can lead the victim into joining an untrusted group chat.
Affected software
Dino
Debian Linux
Ubuntu
Fedora
dino-im (Ubuntu package)
dino-im (Debian package)
dino
Debian Linux
Ubuntu
Fedora
dino-im (Ubuntu package)
dino-im (Debian package)
dino
How to mitigate CVE-2023-28686
Install updates from vendor's website.
Dino - addressed in versions 0.2.3, 0.3.2, 0.4.2
dino-im (Ubuntu package) - update to Ubuntu Pro
dino-im (Debian package) - update to 0.2.0-3+deb11u1
dino - addressed in versions 0.3.2-1.fc36, 0.3.2-1.fc37, 0.4.2-1.fc38
dino-im (Ubuntu package) - update to Ubuntu Pro
dino-im (Debian package) - update to 0.2.0-3+deb11u1
dino - addressed in versions 0.3.2-1.fc36, 0.3.2-1.fc37, 0.4.2-1.fc38