Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.1.0-1ubuntu0.1~esm1", "binary_name": "dino-im" }, { "binary_version": "0.1.0-1ubuntu0.1~esm1", "binary_name": "dino-im-common" }, { "binary_version": "0.1.0-1ubuntu0.1~esm1", "binary_name": "dino-im-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.3.0-3ubuntu0.1~esm1", "binary_name": "dino-im" }, { "binary_version": "0.3.0-3ubuntu0.1~esm1", "binary_name": "dino-im-common" }, { "binary_version": "0.3.0-3ubuntu0.1~esm1", "binary_name": "dino-im-dbgsym" } ] }