CVE-2019-16235: High severity Dino Dino vulnerability
Published Sep 11, 2019
·Updated
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280messagecarbons.vala.
Affected Software
7 affected componentsFixes available
Dino Dino<0.1.0
Canonical Ubuntu Linux=18.04
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Debian Debian Linux=10.0
debian/dino-im
0.2.0-3+deb11u10.4.2-10.5.0-10.5.1-1
Remediation
Event History
Sep 11, 2019
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:51 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·11:51 PM
DescriptionAffected Software
Data Sourced
via Launchpad·11:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16235?
The severity of CVE-2019-16235 is high.
2
What software is affected by CVE-2019-16235?
Dino versions before 2019-09-10 are affected.
3
How can I check if I'm affected by CVE-2019-16235?
You can check if you're affected by CVE-2019-16235 by checking your Dino version. If it is before 2019-09-10, you are affected.
4
How do I fix CVE-2019-16235?
To fix CVE-2019-16235, update your Dino software to version 2019-09-10 or later.
5
Where can I find more information about CVE-2019-16235?
More information about CVE-2019-16235 can be found at the following references: [link1], [link2], [link3].