USN-7430-1: Dino vulnerability
Published Apr 9, 2025
·Updated
Kim Alvefur discovered that Dino did not correctly sanitize certain messages. A remote attacker could possibly use this issue to leak sensitive information.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/dino-im<0.3.0-3ubuntu0.1~esm1
0.3.0-3ubuntu0.1~esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/dino-im<0.1.0-1ubuntu0.1~esm1
0.1.0-1ubuntu0.1~esm1
Ubuntu Ubuntu=20.04
Event History
Apr 9, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7430-1?
USN-7430-1 is considered a medium severity vulnerability due to its potential to leak sensitive information.
2
How do I fix USN-7430-1?
To fix USN-7430-1, you should update the dino-im package to the latest version provided for your Ubuntu release.
3
What systems are affected by USN-7430-1?
USN-7430-1 affects the dino-im package on Ubuntu versions 20.04 and 22.04.
4
What kind of information can be leaked due to USN-7430-1?
USN-7430-1 allows a remote attacker to potentially leak sensitive information through improperly sanitized messages.
5
Who discovered the vulnerability USN-7430-1?
USN-7430-1 was discovered by researcher Kim Alvefur.