Bug 2439270

Summary: CVE-2020-37178 keepass: KeePass: Denial of Service via malicious HTML file drag and drop in help system [fedora-43]
Product: [Fedora] Fedora Reporter: Sandipan Roy <saroy>
Component: keepassAssignee: Julian Sikorski <belegdol>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: 43CC: belegdol, mailinglists, tilmann
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["464d2fcf-baa0-490b-b1f2-9b12487c9d6e"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-03-19 07:32:07 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2439128    

Description Sandipan Roy 2026-02-12 04:09:03 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Dr. Tilmann Bubeck 2026-02-12 06:20:21 UTC
According to https://nvd.nist.gov/vuln/detail/CVE-2020-37178 this only affects KeePass <= 2.44. Therefore I would assume, that this bug does not apply to our packages, as all branches have much newer versions. Close and do nothing?

Comment 2 Julian Sikorski 2026-02-12 09:18:51 UTC
I would say so. To be honest, I do not get what the point of posting a CVE for A six years and sixteen versions old release of particular software is.

Comment 3 Dr. Tilmann Bubeck 2026-02-12 10:26:06 UTC
Closed for all EPEL bugs with text: 
As this CVE is 6 years old and applies only to version 2.44 and before, I do not see the relevance of this bug entry. We have version 2.57 (and newer) in EPEL/Fedora and therefore this problem has been fixed long time ago.
Closing.

Comment 4 Julian Sikorski 2026-03-19 07:32:07 UTC
As this CVE is 6 years old and applies only to version 2.44 and before, I do not see the relevance of this bug entry. We have version 2.57 (and newer) in EPEL/Fedora and therefore this problem has been fixed long time ago.