from store.kde.org. That text is displayed to the user, after turning into a
clickable link any part of the text that looks like a link. This is done for
any kind of link, be it smb:// nfs:// etc. when in fact it only makes sense for
http/https links. Opening links that the user has clicked on is not very
problematic but can be used to chain to other attack vectors. Given the
intended functionality of the feature is just for http/https links it makes
sense to do that verification (CVE-2021-28117).
- https://bugs.mageia.org/show_bug.cgi?id=28581
- https://kde.org/info/security/advisory-20210310-1.txt
- https://www.cve.org/CVERecord?id=CVE-2021-28117
- 8/core/discover-5.20.4-3.1.mga8
- 7/core/discover-5.15.4-2.2.mga7
Get the latest Linux and open source security news straight to your inbox.