Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-32900

Опубликовано: 05 дек. 2025
Источник: debian
EPSS Низкий

Описание

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kdeconnectfixed25.04.0-1package
kdeconnectignoredbookwormpackage
kdeconnectignoredbullseyepackage
gnome-shell-extension-gsconnectfixed62-1package
gnome-shell-extension-gsconnectignoredbookwormpackage

Примечания

  • https://kde.org/info/security/advisory-20250418-2.txt

  • Fixed by: https://invent.kde.org/network/kdeconnect-kde/-/commit/98256fda3dfdf50edd7555f21cba46fd1e596523 (v25.03.80)

  • Fixed by: https://github.com/GSConnect/gnome-shell-extension-gsconnect/commit/cf099c63c7981e69bd095fcbe3215cf87b5328f8 (v59)

EPSS

Процентиль: 1%
0.00012
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

CVSS3: 4.3
nvd
2 месяца назад

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

CVSS3: 4.3
github
2 месяца назад

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

EPSS

Процентиль: 1%
0.00012
Низкий