Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Unable to clear from detected program threat list

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
And, this specific program:
KeePass Password Safe 2.x

This thread has been marked as locked.
rdwann60@gmail.com Unable to clear from detected program threat list
Member 14th Sep, 2010 08:14
Ranking: 0
Posts: 1
User Since: 7th Apr, 2010
System Score: N/A
Location: N/A
Last edited on 14th Sep, 2010 08:15

I have updated Keepass Password Safe 2.x several times and rescanned with Secunia, yet this program will not clear from the detected threat list.... any ideas?

This user no longer exists RE: Unable to clear from detected program threat list
Member 14th Sep, 2010 09:17
Hi,

I have been unable to reproduce this issue. When installing KeePass 2.1.3, the Insecurity is removed from the list. Have you tried installing this version of KeePass? http://ftp.secunia.com/KeePass-2.13-Setup.exe

And if so, which version is displayed in the PSI after you install the above version and run a full rescan?

hope this helps.
Was this reply relevant?
+0
-0
ddmarshall RE: Unable to clear from detected program threat list
Dedicated Contributor 14th Sep, 2010 21:22
Score: 1209
Posts: 961
User Since: 8th Nov 2008
System Score: 98%
Location: UK
Emil,
I've got the same problem.
KeePass 2.1.3.0 is listed twice under patched.
C:\Program Files\KeePass Password Safe 2\KeePass.exe and
C:\Windows\assembly\NativeImages_v2.0.5727_32\KeeP ass\<hex>\KeePass.ni.exe

KeePas 2.1.2.0 is listed once under insecure.
C:\Windows\assembly\NativeImages_v2.0.5727_32\KeeP ass\<hex>\KeePass.ni.exe

When KeePass is installed using the 'Optimize Performance' option, the IL is precompiled into the Native Image Cache by .NET Framework. I don't know why KeePass isn't deleting the old version when it's updated.

--
This answer is provided “as-is.” You bear the risk of using it.
Was this reply relevant?
+0
-0
jerrykehoe RE: Unable to clear from detected program threat list
Member 14th Sep, 2010 23:53
Score: 0
Posts: 2
User Since: 5th Feb 2008
System Score: N/A
Location: N/A
exact same description and problem.

I own the Vista folder (windows\assembly\) and there is no such file apparent.
Was this reply relevant?
+0
-0
jerrykehoe RE: Unable to clear from detected program threat list
Member 15th Sep, 2010 04:08
Score: 0
Posts: 2
User Since: 5th Feb 2008
System Score: N/A
Location: N/A
Same is true on an XP Pro machine.

The notice is for KeePass 2.1.2 but version 2.1.3 is now installed. Old news if it's news at all.
Was this reply relevant?
+0
-0
This user no longer exists RE: Unable to clear from detected program threat list
Member 15th Sep, 2010 10:50
Hi,

Since the C:\windows\assembly\ path isn't an installer location, I have excluded it from our scan rules for KeyPass 2.x. If you run a full rescan, you should be flagged as secure.

hope this helps.
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability