CVE-2023-28686: Debian Linux

High severity, CVSS 7.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Dino Dino: before 0.2.3 (fixed in 0.2.3); from 0.3.0, before 0.3.2 (fixed in 0.3.2); from 0.4.0, before 0.4.2 (fixed in 0.4.2)
  • Fedoraproject Fedora: version 36 only; version 37 only; version 38 only

Published 2023-03-24. Last modified 2026-06-17.