Vietnam.vn - Nền tảng quảng bá Việt Nam

Security flaw causes KeePass to expose master password

Báo Thanh niênBáo Thanh niên22/05/2023


According to Bleeping Computer , a newly discovered memory dump vulnerability in the KeePass application could allow attackers to retrieve master passwords in plain text even if the database is locked or the program is closed. A patch for this critical vulnerability will not be available until early June at the earliest.

A security researcher reported the vulnerability, and published a proof-of-concept exploit that allowed an attacker to extract the master password in plaintext, even if the KeePass database was closed, the program was locked, or not even open. When retrieved from memory, the first one or two characters of the password would be missing, but the entire string could then be guessed.

The exploit was written for Windows, but Linux and macOS are also believed to be vulnerable because the issue exists within KeePass and not in the operating system. To exploit the password, an attacker would need access to a remote computer (gained via malware) or directly on the victim machine.

According to the security expert, all versions of KeePass 2.x are affected. But KeePass 1.x, KeePassXC, and Strongbox - other password managers compatible with KeePass database files - are not affected.

The fix will be included in KeePass version 2.54, which could be released in early June.

Lỗ hổng bảo mật khiến KeePass lộ mật khẩu chính không bị mã hóa   - Ảnh 1.

New security flaw puts KeePass at risk as no patch is available yet

There is now an unstable test version of KeePass with mitigations in place, but a report from Bleeping Computer says the security researcher has been unable to reproduce the password theft from the vulnerability.

However, even after KeePass is upgraded to a fixed version, passwords can still be viewed in the program's memory files. For complete protection, users need to completely wipe the computer by overwriting existing data, then reinstall a new operating system.

Experts advise that a good antivirus program will minimize the possibility, and that users should change their KeePass master password once the official version is available.



Source link

Comment (0)

No data
No data
Admire the million-year-old Chu Dang Ya volcano in Gia Lai
It took Vo Ha Tram 6 weeks to complete the music project praising the Fatherland.
Hanoi coffee shop is bright with red flags and yellow stars to celebrate the 80th anniversary of National Day September 2nd
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground
Watch helicopters rehearse in the sky of Hanoi in preparation for National Day September 2
U23 Vietnam radiantly brought home the Southeast Asian U23 Championship trophy
Northern islands are like 'rough gems', cheap seafood, 10 minutes by boat from the mainland
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony

Heritage

Figure

Business

No videos available

News

Political System

Local

Product