CVE-2020-37178
Description
A flaw was found in KeePass. Attackers can exploit a denial of service vulnerability in the help system's HTML handling by dragging and dropping malicious HTML files into the help area. This action can lead to application instability or a crash, resulting in a denial of service.
Statement
IMPORTANT: KeePass is vulnerable to a denial of service due to improper handling of HTML content within its help system. An attacker could exploit this by tricking a user into dragging and dropping a specially crafted malicious HTML file into the application's help area, leading to application instability or a crash. This affects KeePass installations in Red Hat Community Projects.
Mitigation
Users should avoid dragging and dropping untrusted HTML files into the KeePass help system to prevent triggering the denial of service vulnerability.
Understanding the Weakness (CWE)
Integrity
Technical Impact: Unexpected State
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.