UBUNTU-CVE-2024-33901

Source
https://ubuntu.com/security/CVE-2024-33901
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-33901
Withdrawn
2025-06-23T15:58:13Z
Published
2024-05-20T21:15:00Z
Modified
2024-05-20T21:15:00Z
Summary
[none]
Details

** DISPUTED ** Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

References

Affected packages

Ubuntu:Pro:18.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.2-1
2.2.3+dfsg.1-1
2.2.4+dfsg.1-1
2.3.0+dfsg.1-0ubuntu2
2.3.1+dfsg.1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"

Ubuntu:20.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.3+dfsg.1-1
2.4.3+dfsg.1-1build1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"

Ubuntu:22.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.6+dfsg.1-1~exp1
2.6.6+dfsg.1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"

Ubuntu:24.04:LTS / keepassxc

Package

Name
keepassxc
Purl
pkg:deb/ubuntu/keepassxc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.4+dfsg.1-2
2.7.6+dfsg.1-1
2.7.6+dfsg.1-1build2
2.7.6+dfsg.1-1build3

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"