Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2021-0146 Moderate Security Advisory for Discover Application

mageia
Calendar Grey March 18, 2021
Dist Mageia Esm H88
MGASA-2021-0146 addresses a vulnerability in discover for Mageia versions 7 and 8, ensuring enhanced security.
Discover fetches the description and related texts of some applications/plugins from store.kde.org

Summary

from store.kde.org. That text is displayed to the user, after turning into a clickable link any part of the text that looks like a link. This is done for any kind of link, be it smb:// nfs:// etc. when in fact it only makes sense for http/https links. Opening links that the user has clicked on is not very problematic but can be used to chain to other attack vectors. Given the intended functionality of the feature is just for http/https links it makes sense to do that verification (CVE-2021-28117).

References

- https://bugs.mageia.org/show_bug.cgi?id=28581

- https://kde.org/info/security/advisory-20210310-1.txt

- https://www.cve.org/CVERecord?id=CVE-2021-28117

Resolution

SRPMS

- 8/core/discover-5.20.4-3.1.mga8

- 7/core/discover-5.15.4-2.2.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 18 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0146.html
Type: security
CVE: CVE-2021-28117

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here