MGASA-2023-0122

Source
https://advisories.mageia.org/MGASA-2023-0122.html
Import Source
https://advisories.mageia.org/MGASA-2023-0122.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0122
Related
Published
2023-03-31T00:13:46Z
Modified
2023-03-30T23:07:54Z
Summary
Updated dino packages fix security vulnerability
Details

When a Dino client receives a specifically crafted message from an unauthorized sender, it would use information from that message to add, update or remove entries in the user’s personal bookmark store without requiring further user interaction. (CVE-2023-28686)

References
Credits

Affected packages

Mageia:8 / dino

Package

Name
dino
Purl
pkg:rpm/mageia/dino?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.2.3-1.mga8

Ecosystem specific

{
    "section": "core"
}