Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2020-0416 Critical: kdeconnect-kde Network Attack

mageia
Calendar Grey November 13, 2020
Dist Mageia Esm H88
Recent kdeconnect-kde updates address a local network denial of service vulnerability, essential for Mageia users' security.
An attacker on your local network could send maliciously crafted packets to other hosts running kdeconnect on the network, causing them to use large amounts of CPU, memory or netwo...

Summary

An attacker on your local network could send maliciously crafted packets to other hosts running kdeconnect on the network, causing them to use large amounts of CPU, memory or network connections, which could be used in a Denial of Service attack within the network. (CVE-2020-26164)

References

- https://bugs.mageia.org/show_bug.cgi?id=27349

- https://www.openwall.com/lists/oss-security/2020/10/13/4

- https://kde.org/info/security/advisory-20201002-1.txt

- https://www.cve.org/CVERecord?id=CVE-2020-26164

Resolution

SRPMS

- 7/core/kdeconnect-kde-1.3.4-2.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0416.html
Type: security
CVE: CVE-2020-26164

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here