Ubuntu alert USN-7905-1 (kdeconnect)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-7905-1] KDE Connect vulnerability | |
| Date: | Wed, 03 Dec 2025 13:17:13 +0000 | |
| Message-ID: | <E1vQmjJ-0007fy-Iy@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7905-1 December 03, 2025 kdeconnect vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: KDE Connect could allow authentication of impersonated devices. Software Description: - kdeconnect: connect smartphones to your desktop devices Details: It was discovered that KDE Connect incorrectly handled device IDs. An attacker could possibly use this issue to bypass authentication and connect an unpaired device. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 kdeconnect 25.08.1-0ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7905-1 CVE-2025-66270 Package Information: https://launchpad.net/ubuntu/+source/kdeconnect/25.08.1-0...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmkwNyoACgkQcpJm3tlz hgGX5RAAw21BgXe64+XL2EQTLgNtTDYjQhm+PWX18k0x0sRdLXVKtT8ZrmvBN3P9 gl9fPDHiI9BTJRgt2aUfSeCcTGls6oZW68G7k5+yozNhilV7h+vPFa52Lhwd5K7T Z6AGzWCH3TZ7z6Q6MJ5XgwCMF7EEJI/YC5KZ7tEKtFjM30SMMOIOEvL1+982IPxz iGcaFUNZBsF0ItEuTvV8PxJmgLYqJvcxYoT8tYko3EyWWt90oGMvFSsHcRHpQWNN cRzTzguGcOJ1V16aaoin3liR7aOPMlU3VJisxUuLG44KBMb+WqPXmKUPchaW6hdZ udNQFbNzkVD9LOAOmtRE4FH0KRU0KjrGleh7JGXlgmbMHj/lSABFmXse3yxz1HHd kFItQ6TP52L4edircjvbAyKzvC6HmgwNqBqeY2KVX7c2c9u5eVeEl/C/b69ewpD+ y8ptWT33OSo/SWrlFD1AGN0+44MYRTDmhK2ElXUPDKZvmvG53VaJsqhEU89IyJgI VKW7QwDZcL6rIPrOEzJ0EeE/ZDKEYfyQ6+fAAKMq1FbbqPeCOuEQp1Rr/s3b9uEt uCxcR3iG4sRjbTtVWmvxbZfPFLzTIvxNKouCPhZUV1yOtqAH9quKH80Kdu6X9TZT N13wRgvuWEZksoCBpQXIzVxIzBG0vW7urx5DL2MVLCUuJntjkrU= =EZwY -----END PGP SIGNATURE-----
