Bug 1176268 (CVE-2020-26164) - AUDIT-0: CVE-2020-26164: kdeconnect-kde: review of default-enabled network service in openSUSE Leap 15.2, Tumbleweed
Summary: AUDIT-0: CVE-2020-26164: kdeconnect-kde: review of default-enabled network se...
Status: RESOLVED FIXED
Alias: CVE-2020-26164
Product: SUSE Security Incidents
Classification: Novell Products
Component: Audits (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Luca Beltrame
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/266824/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-09-08 11:40 UTC by Matthias Gerstner
Modified: 2020-12-29 13:10 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Matthias Gerstner 2020-09-08 11:42:05 UTC
This is an embargoed bug. This means that this information is not public. Please
- Do not talk to other people about this unless they're involved in fixing the issue
- Do not make this bug public
- Do not submit this into OBS (e.g. fix Leap) until this bug becomes public (e.g. no EMBARGOED tag on the header)
- Consult security team if you think that the issue is public and the bug is still Embargoed
- Please be aware that the SUSE:SLE-15-SP3:GA codestream is available via OBS.
This means that you can't submit security fixes for embargoed issues to this GA codestream under
development until they become public. In doubt please talk to us on IRC (#security), RocketChat (#security) or send us an e-mail.
Comment 2 Matthias Gerstner 2020-09-08 11:43:34 UTC
Internal CRD: 2020-12-07 preliminary
Comment 3 Matthias Gerstner 2020-09-08 11:47:54 UTC
Created attachment 841471 [details]
tarball containing reproducer script
Comment 5 Matthias Gerstner 2020-09-28 10:59:40 UTC
The preliminary publication date for these issues as communicated by upstream
will be 2020-10-03. We have received a set of bugfixes that I still need to
review.
Comment 6 Matthias Gerstner 2020-09-30 11:20:36 UTC
Created attachment 842110 [details]
patchset against version 20.08
Comment 7 Matthias Gerstner 2020-09-30 11:23:08 UTC
I reviewed the patchset provided by upstream and it fixes all issues described
in the report. You can find the patch in attachment 842110 [details]. Please don't
publish this yet in OBS or anywhere else.

Still missing is a safe pairing procedure. Let's see whether upstream will do
something about it. I raised this issue once more with them.
Comment 9 Matthias Gerstner 2020-10-02 13:11:26 UTC
The individual issues are now public via https://kde.org/info/security/advisory-20201002-1.txt.

Please start submitting updates for all maintained kdeconnect-kde codestreams. Thank you!
Comment 10 Luca Beltrame 2020-10-02 14:19:36 UTC
Thanks, Matthias. We're in the process of preparing updates for 15.1, 15.2 and Tumbleweed.
Comment 11 OBSbugzilla Bot 2020-10-02 16:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (1176268) was mentioned in
https://build.opensuse.org/request/show/839182 15.1 / kdeconnect-kde
https://build.opensuse.org/request/show/839186 15.2 / kdeconnect-kde
Comment 12 OBSbugzilla Bot 2020-10-02 21:20:07 UTC
This is an autogenerated message for OBS integration:
This bug (1176268) was mentioned in
https://build.opensuse.org/request/show/839235 15.1 / kdeconnect-kde
Comment 13 Matthias Gerstner 2020-10-07 11:57:19 UTC
Thank you for submitting the updates.

There is still the topic of the default enablement of the kdeconnectd in
openSUSE installations. Can you please find an approach to avoid that?

A simple approach might be to remove kdeconnect from the default KDE
installation pattern. If a user explicitly installs this package then he
hopefully knows what he does. But exposing all users to the potential risks of
a network service that isn't mature yet and provides these kinds of remote
access features is not okay.
Comment 14 Swamp Workflow Management 2020-10-07 13:14:52 UTC
openSUSE-SU-2020:1631-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1176268
CVE References: CVE-2020-26164
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    kdeconnect-kde-20.04.2-lp152.2.3.1
openSUSE Leap 15.1 (src):    kdeconnect-kde-1.3.3-lp151.2.3.1
Comment 15 Swamp Workflow Management 2020-10-10 16:14:43 UTC
openSUSE-SU-2020:1647-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1176268
CVE References: CVE-2020-26164
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP1 (src):    kdeconnect-kde-1.3.3-bp151.4.3.1
Comment 16 Swamp Workflow Management 2020-10-10 19:15:35 UTC
openSUSE-SU-2020:1650-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1176268
CVE References: CVE-2020-26164
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    kdeconnect-kde-20.04.2-bp152.2.3.1
Comment 17 Matthias Gerstner 2020-12-29 13:10:13 UTC
The audit and its ramifications should be covered by now. Closing.