7.5
CVSSv3

CVE-2015-8378

Published: 10/04/2017 Updated: 15/04/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In KeePassX prior to 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allows context-dependent malicious users to obtain sensitive information by reading the .xml dotfile.

Vulnerable Product Search on Vulmon Subscribe to Product

keepassx project keepassx

Vendor Advisories

Debian Bug report logs - #791858 keepassx: CVE-2015-8378: canceling export operation creates cleartext copy of all of the user's KeePassX password database entries Package: keepassx; Maintainer for keepassx is Debian QA Group <packages@qadebianorg>; Source for keepassx is src:keepassx (PTS, buildd, popcon) Reported by: "m ...