Skip to content

DoS vulnerability: Bad actor can spam the GUI with fingerprint dialogs and stop the server #8253

@nbolton

Description

@nbolton

Project

Deskflow

Deskflow version number

Deskflow: 1.19.0.97 (2da0b3b)
Qt: 6.8.2
System: Fedora Linux 41 (Workstation Edition)
Session: GNOME (wayland)

Build type

Local developer build (built it myself)

OS versions/distros

Any

What steps will reproduce the problem?

  1. Connect to a server
  2. Click 'No' on the fingerprint dialog
  3. Start server
  4. Keep client connecting

Actual: The fingerprint dialog keeps showing forever (and the server is stopped)
Expected: The server should be able to permanently ignore a client (and the server should never stop)

Screencast.From.2025-02-27.10-50-27.mp4

Metadata

Metadata

Assignees

No one assigned

    Labels

    🛡️ securityA security vulnerability (CVE, etc)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions