Vulnerability CVE-2019-16236


Published: 2019-09-11

Description:
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

Type:

CWE-863

(Incorrect Authorization)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://www.openwall.com/lists/oss-security/2019/09/12/5
https://github.com/dino/dino/commit/dd33f5f949248d87d34f399e8846d5ee5b8823d9
https://gultsch.de/dino_multiple.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5TMGQ5Q6QMIFG4NVUWMOWW3GIPGWQZVF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZBNQAOBWTIOKNO4PIYNX624ACGUXSXQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YUBM7GDZBB6MZZALDWYRAPNV6HJNLNMC/
https://seclists.org/bugtraq/2019/Sep/31
https://www.debian.org/security/2019/dsa-4524

Copyright 2024, cxsecurity.com

 

Back to Top