Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 567256 (CVE-2015-8378) - <app-admin/keepassx-0.4.4: passwords stored in plain text file when export is cancelled (CVE-2015-8378)
Summary: <app-admin/keepassx-0.4.4: passwords stored in plain text file when export is...
Status: RESOLVED FIXED
Alias: CVE-2015-8378
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-12-01 13:40 UTC by Agostino Sarubbo
Modified: 2017-01-14 05:11 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-12-01 13:40:38 UTC
From ${URL} :

It was found that XML export function in keepassx 0.4.3 creates hidden XML file containing user 
passwords in plaintext without warning, when the export is cancelled, which may go unnoticed by the 
user.

CVE request:

http://seclists.org/oss-sec/2015/q4/404


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2015-12-14 11:43:30 UTC
commit 40f4c38ff1f938261bac47902b28b6f465aa44b7
Author: Lars Wendler <polynomial-c@gentoo.org>
Date:   Fri Dec 11 15:06:40 2015

    app-admin/keepassx: Security bump to version 0.4.4

    https://www.keepassx.org/news/2015/12/551
    Fixes CVE-2015-8359 and CVE-2015-8378

    Package-Manager: portage-2.2.26
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
Comment 2 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2015-12-14 11:45:11 UTC
By the way, the affected version (0.4.3) has been marked stable in Gentoo, so we need to react here.
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2015-12-21 18:26:26 UTC
Whiteboard corrected: Please advise when ready to go stable
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2016-02-25 06:30:32 UTC
Been in tree for more then 30 days, calling for stabilization.

Arches, please test and mark stable:

=app-admin/keepassx-0.4.4

Target Keywords : "amd64 ppc x86"
Thank you!
Comment 5 Agostino Sarubbo gentoo-dev 2016-03-02 13:59:44 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2016-03-15 16:41:23 UTC
x86 stable
Comment 7 Agostino Sarubbo gentoo-dev 2016-03-16 12:05:05 UTC
ppc stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 8 Yury German Gentoo Infrastructure gentoo-dev 2016-04-26 06:16:17 UTC
Arches, Thank you for your work.
GLSA Vote: Yes
New GLSA Request filed.

Maintainer(s), please drop the vulnerable version(s).
Comment 9 Aaron Bauman (RETIRED) gentoo-dev 2016-06-11 11:23:32 UTC
Cleanup complete and opened for pending GLSA.
Comment 10 Anthony Ryan 2017-01-14 05:05:51 UTC
Bump. This has been resolved in the tree for a while now.
Comment 11 Aaron Bauman (RETIRED) gentoo-dev 2017-01-14 05:11:58 UTC
GLSA is long overdue and not required. 

GLSA Vote: No