Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2023-0122 Moderate: Dino Unauthorized Bookmark Access

mageia
Calendar Grey March 31, 2023
Dist Mageia Esm H88
Dino software patch resolves flaw permitting illicit entry to saved links. Release date: Apr 15, 2023.
When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the userâ€...

Summary

When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the user’s personal bookmark store without requiring further user interaction. (CVE-2023-28686)

References

- https://bugs.mageia.org/show_bug.cgi?id=31726

-

- https://www.cve.org/CVERecord?id=CVE-2023-28686

Resolution

SRPMS

- 8/core/dino-0.2.3-1.mga8

Publication date: 31 Mar 2023
URL: https://advisories.mageia.org/MGASA-2023-0122.html
Type: security
CVE: CVE-2023-28686

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here