Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 7 MGASA-2020-0475 Moderate: kdeconnect-kde Security Enhancement

mageia
Calendar Grey December 29, 2020
Dist Mageia Esm H88
Mageia's latest security patch resolves kdeconnect concerns regarding unencrypted device identifiers; strengthens peer validation protocols.
For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control

Summary

For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control. Furthermore the 'deviceName' is transmitted in cleartext in UDP broadcast messages for all other nodes in the network segment to see. Therefore malicious devices can attempt to confuse users by requesting a

References

- https://bugs.mageia.org/show_bug.cgi?id=27700

- https://www.openwall.com/lists/oss-security/2020/11/30/1

-

Resolution

SRPMS

- 7/core/kdeconnect-kde-1.3.4-2.2.mga7

Publication date: 29 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0475.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here