--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-2e27372d4c
2024-06-05 01:40:23.602023
--------------------------------------------------------------------------------

Name        : keepassxc
Product     : Fedora 40
Version     : 2.7.8
Release     : 2.fc40
URL         : https://keepassxc.org/
Summary     : Cross-platform password manager
Description :
KeePassXC is a community fork of KeePassX
KeePassXC is an application for people with extremely high demands on secure
personal data management.
KeePassXC saves many different information e.g. user names, passwords, urls,
attachemts and comments in one single database. For a better management
user-defined titles and icons can be specified for each single entry.
Furthermore the entries are sorted in groups, which are customizable as well.
The integrated search function allows to search in a single group or the
complete database.
KeePassXC offers a little utility for secure password generation. The password
generator is very customizable, fast and easy to use. Especially someone who
generates passwords frequently will appreciate this feature.
The complete database is always encrypted either with AES (alias Rijndael) or
Twofish encryption algorithm using a 256 bit key. Therefore the saved
information can be considered as quite safe.

--------------------------------------------------------------------------------
Update Information:

Qt 5.15.14 bugfix update.
Fix CVE-2024-36048
--------------------------------------------------------------------------------
ChangeLog:

* Thu May 30 2024 Jan Grulich  - 2.7.8-2
- Rebuild (qt5)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2282866 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [epel-8]
        https://bugzilla.redhat.com/show_bug.cgi?id=2282866
  [ 2 ] Bug #2282867 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-39]
        https://bugzilla.redhat.com/show_bug.cgi?id=2282867
  [ 3 ] Bug #2282869 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-40]
        https://bugzilla.redhat.com/show_bug.cgi?id=2282869
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-2e27372d4c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Fedora 40: keepassxc 2024-2e27372d4c Security Advisory Updates

June 5, 2024
Qt 5.15.14 bugfix update

Summary

KeePassXC is a community fork of KeePassX

KeePassXC is an application for people with extremely high demands on secure

personal data management.

KeePassXC saves many different information e.g. user names, passwords, urls,

attachemts and comments in one single database. For a better management

user-defined titles and icons can be specified for each single entry.

Furthermore the entries are sorted in groups, which are customizable as well.

The integrated search function allows to search in a single group or the

complete database.

KeePassXC offers a little utility for secure password generation. The password

generator is very customizable, fast and easy to use. Especially someone who

generates passwords frequently will appreciate this feature.

The complete database is always encrypted either with AES (alias Rijndael) or

Twofish encryption algorithm using a 256 bit key. Therefore the saved

information can be considered as quite safe.

Update Information:

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

Change Log

* Thu May 30 2024 Jan Grulich - 2.7.8-2 - Rebuild (qt5)

References

[ 1 ] Bug #2282866 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2282866 [ 2 ] Bug #2282867 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2282867 [ 3 ] Bug #2282869 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2282869

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2e27372d4c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
Name : keepassxc
Product : Fedora 40
Version : 2.7.8
Release : 2.fc40
URL : https://keepassxc.org/
Summary : Cross-platform password manager

Related News