{"id":"UBUNTU-CVE-2024-33901","details":"** DISPUTED ** Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.","modified":"2024-05-20T21:15:00Z","published":"2024-05-20T21:15:00Z","withdrawn":"2025-06-23T15:58:13Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-33901"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-33901"},{"type":"REPORT","url":"https://keepassxc.org/blog/"},{"type":"REPORT","url":"https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838"}],"affected":[{"package":{"name":"keepassxc","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/keepassxc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.2-1","2.2.3+dfsg.1-1","2.2.4+dfsg.1-1","2.3.0+dfsg.1-0ubuntu2","2.3.1+dfsg.1-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"}},{"package":{"name":"keepassxc","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/keepassxc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.3+dfsg.1-1","2.4.3+dfsg.1-1build1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"}},{"package":{"name":"keepassxc","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/keepassxc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.6+dfsg.1-1~exp1","2.6.6+dfsg.1-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"}},{"package":{"name":"keepassxc","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/keepassxc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.4+dfsg.1-2","2.7.6+dfsg.1-1","2.7.6+dfsg.1-1build2","2.7.6+dfsg.1-1build3"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33901.json"}}],"schema_version":"1.7.3"}