For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control. Furthermore the 'deviceName' is transmitted in cleartext in UDP broadcast messages for all other nodes in the network segment to see. Therefore malicious devices can attempt to confuse users by requesting a . MGASA-2020-0475 - Updated kdeconnect-kde packages improve security Publication date: 29 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0475.html Type: security Affected Mageia releases: 7 For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control. Furthermore the 'deviceName' is transmitted in cleartext in UDP broadcast messages for all other nodes in the network segment to see. Therefore malicious devices can attempt to confuse users by requesting a pairing under the same 'deviceName' to gain access to a system. Now, a sha256 fingerprint of the concatenated public keys of the two involved certificates is displayed. In the initial popup, a prefix of 8 hex digits of the fingerprint is displayed. The full fingerprint is reachable via an additional "view key" button. References: - https://bugs.mageia.org/show_bug.cgi?id=27700 - https://www.openwall.com/lists/oss-security/2020/11/30/1 - SRPMS: - 7/core/kdeconnect-kde-1.3.4-2.2.mga7 . Mageia's latest security patch resolves kdeconnect concerns regarding unencrypted device identifiers; strengthens peer validation protocols.. Kdeconnect Security, Mageia Update, Peer Authentication, Network Security, Cleartext Risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.