CVE-2020-37178

Description

A flaw was found in KeePass. Attackers can exploit a denial of service vulnerability in the help system's HTML handling by dragging and dropping malicious HTML files into the help area. This action can lead to application instability or a crash, resulting in a denial of service.

Statement

IMPORTANT: KeePass is vulnerable to a denial of service due to improper handling of HTML content within its help system. An attacker could exploit this by tricking a user into dragging and dropping a specially crafted malicious HTML file into the application's help area, leading to application instability or a crash. This affects KeePass installations in Red Hat Community Projects.

Mitigation

Users should avoid dragging and dropping untrusted HTML files into the KeePass help system to prevent triggering the denial of service vulnerability.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Unexpected State

Frequently Asked Questions

Want to get errata notifications? Sign up here.