Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: MGASA-2023-0222 High: Keepass Vulnerability in Cleartext Access

mageia
Calendar Grey July 7, 2023
Dist Mageia Esm H88
Recent KeePass updates in Mageia 8 tackle vulnerabilities concerning the exposure of unencrypted passwords. Discover further details.
Allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger

Summary

Allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. Disputed by vendor due to level of access required. (CVE-2023-24055) Possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running (CVE-2023-32784)

References

- https://bugs.mageia.org/show_bug.cgi?id=31935

-

- https://www.cve.org/CVERecord?id=CVE-2023-24055

- https://www.cve.org/CVERecord?id=CVE-2023-32784

Resolution

SRPMS

- 8/core/keepass-2.54-1.mga8

Publication date: 07 Jul 2023
URL: https://advisories.mageia.org/MGASA-2023-0221.html
Type: security
CVE: CVE-2023-24055, CVE-2023-32784

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here