The vulnerability that allowed man-in-the-middle attacks in the popular password manager KeePass has reportedly been fixed in the new KeePass 2.34 update.
The attacker was able to successfully exploit the technique used by older versions of KeePass to check for new updates. The application did not verify the information coming from the KeePass server nor did it use a secure transport protocol to transmit the update to the user's system.
This way the attacker could manipulate the information and deliver a malicious copy of KeePass to the end user.
So at this time it is recommended to download the new KeePass 2.34 version from the project website or from the links below and not automatically from your application.
The new KeePass 2.34 release fixes the update check issue by sending version information over HTTPS, and digitally signing it. So from today, it will only accept version information files that have a digital signature.
All KeePass executables are signed, and it is quite easy to verify that the digital signature is correct. To verify the signature, open the KeePass directory on your system, right-click on any executable file, select Properties from the menu, and view the “digital signatures.”
The signature should say “Open Source Developer, Dominik Reichl.” If it doesn’t, delete the files immediately and scan your computer with a reputable antivirus.
It should be mentioned that the application is one of the few of its kind that we prefer, as it stores passwords encrypted, locally and not somewhere on the internet.
KeePass 2.34
Installer:
Portable:
Supported operating systems:
Windows 98 / 98SE / ME / 2000 / XP / 2003 / Vista / 7 / 8 / 10, each 32-bit and 64-bit, Mono (Linux, Mac OS X, BSD, ...).
Prerequisites:
Microsoft .NET Framework ≥ 2.0 (already included in Windows Vista and higher) or Mono ≥ 2.6.
