KDE Connect: Denial of service — GLSA 202101-16

A vulnerability in KDE Connect could lead to a Denial of Service condition.

Affected packages

kde-misc/kdeconnect on all architectures
Affected versions < 20.04.3-r1
Unaffected versions >= 20.04.3-r1

Background

KDE Connect is a project that enables all your devices to communicate with each other.

Description

Multiple issues causing excessive resource consumption were found in KDE Connect.

Impact

An attacker could cause a possible Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All KDE Connect users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=kde-misc/kdeconnect-20.04.3-r1"
 

References

Release date
January 22, 2021

Latest revision
January 22, 2021: 1

Severity
normal

Exploitable
remote

Bugzilla entries