Bug 27297 - kio-extras new security issue CVE-2020-12755
Summary: kio-extras new security issue CVE-2020-12755
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-09-20 18:29 CEST by David Walser
Modified: 2020-09-27 22:07 CEST (History)
4 users (show)

See Also:
Source RPM: kio-extras-19.04.0-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-09-20 18:29:36 CEST
KDE has issued an advisory on May 10:
https://kde.org/info/security/advisory-20200510-1.txt

The issue was fixed upstream in 20.04.1 and the commit that fixed it is linked in the advisory.
Comment 1 David GEIGER 2020-09-22 07:03:47 CEST
Done for mga7!

CC: (none) => geiger.david68210

Comment 2 David Walser 2020-09-22 15:45:49 CEST
Advisory:
========================

Updated kio-extras packages fix security vulnerability:

fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through
20.04.0 makes a cacheAuthentication call even if the user had not set the
keepPassword option. This may lead to unintended KWallet storage of the
password (CVE-2020-12755).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12755
https://kde.org/info/security/advisory-20200510-1.txt
========================

Updated packages in core/updates_testing:
========================
kio-extras-19.04.0-1.1.mga7
libmolletnetwork19-19.04.0-1.1.mga7
libkioarchive5-19.04.0-1.1.mga7
libkioarchive-devel-19.04.0-1.1.mga7
kio-extras-handbook-19.04.0-1.1.mga7

from kio-extras-19.04.0-1.1.mga7.src.rpm

Assignee: kde => qa-bugs

Comment 3 Herman Viaene 2020-09-23 16:43:31 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
Ref  bug 23868 refers to thumbnails in Plasma- dolphin.
Checked a lot of different file types in dolphin and found no diffferences with situation as before the update.
So far, so good.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 4 Aurelien Oudelet 2020-09-23 17:43:30 CEST
Validated update, Advisory and packages in Comment 2.

CC: (none) => ouaurelien, sysadmin-bugs
Keywords: (none) => advisory, validated_update

Comment 5 Mageia Robot 2020-09-27 22:07:52 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0371.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.