MGASA-2020-0475

Source
https://advisories.mageia.org/MGASA-2020-0475.html
Import Source
https://advisories.mageia.org/MGASA-2020-0475.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0475
Published
2020-12-29T11:57:17Z
Modified
2026-04-16T04:25:31.953316Z
Summary
Updated kdeconnect-kde packages improve security
Details

For the pairing procedure, the GUI component only presented the friendly 'deviceName' to identify peer devices, which is completely under attacker control. Furthermore the 'deviceName' is transmitted in cleartext in UDP broadcast messages for all other nodes in the network segment to see. Therefore malicious devices can attempt to confuse users by requesting a pairing under the same 'deviceName' to gain access to a system.

Now, a sha256 fingerprint of the concatenated public keys of the two involved certificates is displayed. In the initial popup, a prefix of 8 hex digits of the fingerprint is displayed. The full fingerprint is reachable via an additional "view key" button.

References
Credits

Affected packages

Mageia:7 / kdeconnect-kde

Package

Name
kdeconnect-kde
Purl
pkg:rpm/mageia/kdeconnect-kde?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.4-2.2.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2020-0475.json"