For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control. Furthermore the 'deviceName' is transmitted in cleartext in UDP broadcast messages for all other nodes in the network segment to see. Therefore malicious devices can attempt to confuse users by requesting a
- https://bugs.mageia.org/show_bug.cgi?id=27700
- https://www.openwall.com/lists/oss-security/2020/11/30/1
-
- 7/core/kdeconnect-kde-1.3.4-2.2.mga7
Get the latest Linux and open source security news straight to your inbox.