CVE-2016-5119: Input Validation
Published Jan 23, 2017
·Updated
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.
Affected Software
1 affected component
KeePass KeePass<=2.33
Remediation
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5119?
CVE-2016-5119 has a high severity level due to the potential for remote code execution by an attacker.
2
How do I fix CVE-2016-5119?
To mitigate CVE-2016-5119, upgrade to a version of KeePass later than 2.33.
3
What type of attack does CVE-2016-5119 involve?
CVE-2016-5119 involves a man-in-the-middle attack that can exploit the automatic update feature.
4
Which versions of KeePass are affected by CVE-2016-5119?
KeePass versions 2.33 and earlier are affected by CVE-2016-5119.
5
What are the consequences of exploiting CVE-2016-5119?
An attacker exploiting CVE-2016-5119 can execute arbitrary code on the user's system.