First published: Wed Oct 07 2020(Updated: )
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kde Kdeconnect | <20.08.2 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Backports SLE | =15.0-sp2 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26164 is a vulnerability in kdeconnect-kde (aka KDE Connect) before 20.08.2 that allows an attacker on the local network to send crafted packets that trigger a Denial of Service attack.
The severity of CVE-2020-26164 is medium, with a severity value of 5.5.
An attacker can exploit CVE-2020-26164 by sending crafted packets on the local network to trigger a Denial of Service attack.
Versions of kdeconnect-kde (aka KDE Connect) before 20.08.2 are affected by CVE-2020-26164.
To mitigate CVE-2020-26164, it is recommended to update to version 20.08.2 or later of kdeconnect-kde (aka KDE Connect).