In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26164
Reference (s):
- https://kde.org/info/security/advisory-20201002-1.txt
- https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00014.html
- GENTOO:GLSA-202101-16
- URL: https://security.gentoo.org/glsa/202101-16
- https://bugzilla.suse.com/show_bug.cgi?id=1176268

