CVE-2023-28686: Debian Linux
High severity, CVSS 7.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Dino Dino: before 0.2.3 (fixed in 0.2.3); from 0.3.0, before 0.3.2 (fixed in 0.3.2); from 0.4.0, before 0.4.2 (fixed in 0.4.2)
- Fedoraproject Fedora: version 36 only; version 37 only; version 38 only
Published 2023-03-24. Last modified 2026-06-17.