CVE-2019-16236: High severity Dino Dino vulnerability
Published Sep 11, 2019
·Updated
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
Affected Software
7 affected componentsFixes available
Dino Dino<0.1.0
Canonical Ubuntu Linux=18.04
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Debian Debian Linux=10.0
debian/dino-im
0.2.0-3+deb11u10.4.2-10.5.0-10.5.1-1
Remediation
Event History
Sep 11, 2019
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:51 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·11:51 PM
DescriptionAffected Software
Data Sourced
via Launchpad·11:52 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16236?
CVE-2019-16236 is a vulnerability in Dino where it does not check roster push authorization.
2
How does CVE-2019-16236 affect Dino?
CVE-2019-16236 affects Dino by allowing unauthorized roster push.
3
What is the severity of CVE-2019-16236?
The severity of CVE-2019-16236 is high with a CVSS score of 7.5.
4
What software versions are affected by CVE-2019-16236?
CVE-2019-16236 affects Dino versions 0.0.git20181129-1+deb10u1, 0.2.0-3+deb11u1, 0.4.2-1, and 0.4.3-2.
5
How can I fix CVE-2019-16236?
To fix CVE-2019-16236, update Dino to a version that includes the fix.