Dino could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7430-1 April 09, 2025 dino-im vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Dino could be made to expose sensitive information over the network. Software Description: - dino-im: modern XMPP client Details: Kim Alvefur discovered that Dino did not correctly sanitize certain messages. A remote attacker could possibly use this issue to leak sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS dino-im 0.3.0-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS dino-im 0.1.0-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7430-1 CVE-2023-28686 . Discover the method to resolve the dino-im security vulnerability in Ubuntu which reveals confidential data through network channels.. Ubuntu Security, dino-im, Information Leak, Remote Threat. . Severity: Critical. LinuxSecurity.com Team
Maintenance release with fix for CVE-2023-28686 and bug fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-f003d8e633 2023-04-01 01:20:38.373945 --------------------------------------------------------------------------------Name : dino Product : Fedora 37 Version : 0.3.2 Release : 1.fc37 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Maintenance release with fix for CVE-2023-28686 and bug fixes. --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #2181357 - CVE-2023-28686 dino: Insufficient message sender validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2181357 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f003d8e633' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Maintenance release with fix for CVE-2023-28686 and bug fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-587d6a00c3 2023-04-01 00:42:10.067197 --------------------------------------------------------------------------------Name : dino Product : Fedora 36 Version : 0.3.2 Release : 1.fc36 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Maintenance release with fix for CVE-2023-28686 and bug fixes. --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #2181357 - CVE-2023-28686 dino: Insufficient message sender validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2181357 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-587d6a00c3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the userâs personal bookmark store without requiring further user interaction. (CVE-2023-28686) . MGASA-2023-0122 - Updated dino packages fix security vulnerability Publication date: 31 Mar 2023 URL: https://advisories.mageia.org/MGASA-2023-0122.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-28686 When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the userâs personal bookmark store without requiring further user interaction. (CVE-2023-28686) References: - https://bugs.mageia.org/show_bug.cgi?id=31726 - - https://www.cve.org/CVERecord?id=CVE-2023-28686 SRPMS: - 8/core/dino-0.2.3-1.mga8 . Dino software patch resolves flaw permitting illicit entry to saved links. Release date: Apr 15, 2023.. Mageia Security,Dino Update,Security Patch,Unauthorized Access,Bookmark Exploit. . LinuxSecurity.com Team
Update for [CVE-2021-33896]().. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-d5d263ec35 2021-06-16 20:45:00.322530 --------------------------------------------------------------------------------Name : dino Product : Fedora 34 Version : 0.2.1 Release : 1.fc34 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Update for [CVE-2021-33896](). --------------------------------------------------------------------------------ChangeLog: * Mon Jun 7 2021 Randy Barlow - 0.2.1-1 - CVE-2021-33896: Update to 0.2.1 (#1968753). --------------------------------------------------------------------------------References: [ 1 ] Bug #1968753 - CVE-2021-33896: Path traversal in Dino file transfers https://bugzilla.redhat.com/show_bug.cgi?id=1968753 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-d5d263ec35' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update dino to [a96c8014](https://github.com/dino/dino/compare/016ab2c1...a96c8014), which addresses three CVEs. CVE-2019-16235 check the source of message carbons. https://nvd.nist.gov/vuln/detail/CVE-2019-16235 Fixed in. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-0eb6d51f81 2019-09-20 01:33:15.991594 --------------------------------------------------------------------------------Name : dino Product : Fedora 29 Version : 0.0 Release : 0.12.20190912.git.a96c801.fc29 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Update dino to [a96c8014](https://github.com/dino/dino/compare/016ab2c1...a96c8014), which addresses three CVEs. CVE-2019-16235 ============== Dino did not properly check the source of message carbons. https://nvd.nist.gov/vuln/detail/CVE-2019-16235 Fixed in https://github.com/dino/dino/commit/e84f2c49567e86d2a261ea264d65c4adc549c930 CVE-2019-16236 ========== Dino did not check roster push authorization. https://nvd.nist.gov/vuln/detail/CVE-2019-16236 Fixed in https://github.com/dino/dino/commit/dd33f5f949248d87d34f399e8846d5ee5b8823d9 CVE-2019-16237 ========== Dinot did not properly check the source of MAM messages. https://nvd.nist.gov/vuln/detail/CVE-2019-16237 Fixed in https://github.com/dino/dino/commit/307f16cc86dd2b95aa02ab8a85110e4a2d5e7363 --------------------------------------------------------------------------------References: [ 1 ] Bug #1751851 - CVE-2019-16237: dino does not properly check the source of an MAM messages https://bugzilla.redhat.com/show_bug.cgi?id=1751851 [ 2 ] Bug #1751849 - CVE-2019-16236: dino does not check roster push authorization https://bugzilla.redhat.com/show_bug.cgi?id=1751849 [ 3] Bug #1751847 - CVE-2019-16235: Dino before does not properly check the source of a carbons https://bugzilla.redhat.com/show_bug.cgi?id=1751847 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-0eb6d51f81' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update dino to [a96c8014](https://github.com/dino/dino/compare/016ab2c1...a96c8014), which addresses three CVEs. CVE-2019-16235 check the source of message carbons. https://nvd.nist.gov/vuln/detail/CVE-2019-16235 Fixed in. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-3d3bb765ca 2019-09-20 01:21:28.248407 --------------------------------------------------------------------------------Name : dino Product : Fedora 30 Version : 0.0 Release : 0.12.20190912.git.a96c801.fc30 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Update dino to [a96c8014](https://github.com/dino/dino/compare/016ab2c1...a96c8014), which addresses three CVEs. CVE-2019-16235 ============== Dino did not properly check the source of message carbons. https://nvd.nist.gov/vuln/detail/CVE-2019-16235 Fixed in https://github.com/dino/dino/commit/e84f2c49567e86d2a261ea264d65c4adc549c930 CVE-2019-16236 ========== Dino did not check roster push authorization. https://nvd.nist.gov/vuln/detail/CVE-2019-16236 Fixed in https://github.com/dino/dino/commit/dd33f5f949248d87d34f399e8846d5ee5b8823d9 CVE-2019-16237 ========== Dinot did not properly check the source of MAM messages. https://nvd.nist.gov/vuln/detail/CVE-2019-16237 Fixed in https://github.com/dino/dino/commit/307f16cc86dd2b95aa02ab8a85110e4a2d5e7363 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 12 2019 Randy Barlow - 0.0-0.12.20190912.git.a96c8014 - Update to a96c8014. - Fixes CVE-2019-16235 (#1751847), CVE-2019-16236 (#1751849), and CVE-2019-16237 (#1751851). - https://github.com/dino/dino/compare/016ab2c1...a96c8014 * Sat Aug 31 2019 Randy Barlow - 0.0-0.12.20190830.git.016ab2c1 -Update to 016ab2c1. - https://github.com/dino/dino/compare/8120203d...016ab2c1 * Mon Jun 3 2019 Randy Barlow - 0.9.20190601.git.8120203d - Correct the commit date in the Release field, it was a typo in the prior commit. * Sat Jun 1 2019 Randy Barlow - 0.8.20190701.git.git.8120203d - Update to 8120203d. - https://github.com/dino/dino/compare/f4778ef3...8120203d * Sun May 5 2019 Randy Barlow - 0.0-0.7.20190429.git.f4778ef3 - Update to f4778ef3. - https://github.com/dino/dino/compare/330649a...f4778ef3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1751851 - CVE-2019-16237: dino does not properly check the source of an MAM messages https://bugzilla.redhat.com/show_bug.cgi?id=1751851 [ 2 ] Bug #1751849 - CVE-2019-16236: dino does not check roster push authorization https://bugzilla.redhat.com/show_bug.cgi?id=1751849 [ 3 ] Bug #1751847 - CVE-2019-16235: Dino before does not properly check the source of a carbons https://bugzilla.redhat.com/show_bug.cgi?id=1751847 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-3d3bb765ca' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update dino to [a96c8014](https://github.com/dino/dino/compare/016ab2c1...a96c8014), which addresses three CVEs. CVE-2019-16235 check the source of message carbons. https://nvd.nist.gov/vuln/detail/CVE-2019-16235 Fixed in. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-2555c77f63 2019-09-18 00:01:15.682637 --------------------------------------------------------------------------------Name : dino Product : Fedora 31 Version : 0.0 Release : 0.13.20190912.git.a96c801.fc31 URL : https://github.com/dino/dino Summary : Modern XMPP ("Jabber") Chat Client using GTK+/Vala Description : A modern XMPP ("Jabber") chat client using GTK+/Vala. --------------------------------------------------------------------------------Update Information: Update dino to [a96c8014](https://github.com/dino/dino/compare/016ab2c1...a96c8014), which addresses three CVEs. CVE-2019-16235 ============== Dino did not properly check the source of message carbons. https://nvd.nist.gov/vuln/detail/CVE-2019-16235 Fixed in https://github.com/dino/dino/commit/e84f2c49567e86d2a261ea264d65c4adc549c930 CVE-2019-16236 ========== Dino did not check roster push authorization. https://nvd.nist.gov/vuln/detail/CVE-2019-16236 Fixed in https://github.com/dino/dino/commit/dd33f5f949248d87d34f399e8846d5ee5b8823d9 CVE-2019-16237 ========== Dinot did not properly check the source of MAM messages. https://nvd.nist.gov/vuln/detail/CVE-2019-16237 Fixed in https://github.com/dino/dino/commit/307f16cc86dd2b95aa02ab8a85110e4a2d5e7363 --------------------------------------------------------------------------------References: [ 1 ] Bug #1751851 - CVE-2019-16237: dino does not properly check the source of an MAM messages https://bugzilla.redhat.com/show_bug.cgi?id=1751851 [ 2 ] Bug #1751849 - CVE-2019-16236: dino does not check roster push authorization https://bugzilla.redhat.com/show_bug.cgi?id=1751849 [ 3] Bug #1751847 - CVE-2019-16235: Dino before does not properly check the source of a carbons https://bugzilla.redhat.com/show_bug.cgi?id=1751847 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-2555c77f63' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.