When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the userâs personal bookmark store without requiring further user interaction. (CVE-2023-28686) . MGASA-2023-0122 - Updated dino packages fix security vulnerability Publication date: 31 Mar 2023 URL: https://advisories.mageia.org/MGASA-2023-0122.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-28686 When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the userâs personal bookmark store without requiring further user interaction. (CVE-2023-28686) References: - https://bugs.mageia.org/show_bug.cgi?id=31726 - - https://www.cve.org/CVERecord?id=CVE-2023-28686 SRPMS: - 8/core/dino-0.2.3-1.mga8 . Dino software patch resolves flaw permitting illicit entry to saved links. Release date: Apr 15, 2023.. Mageia Security,Dino Update,Security Patch,Unauthorized Access,Bookmark Exploit. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.