FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

dino -- Insufficient message sender validation in Dino

Affected packages
dino < 0.4.2

Details

VuXML ID dec6b8e9-c9fe-11ed-bb39-901b0e9408dc
Discovery 2023-03-23
Entry 2023-03-24

Dino team reports:

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.

References

CVE Name CVE-2023-28686
URL https://dino.im/security/cve-2023-28686/