SB2019070823 - Use of a broken or risky cryptographic algorithm in Dropbox for Windows
Published: July 8, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of a broken or risky cryptographic algorithm (CVE-ID: CVE-2019-12171)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.
Remediation
Install update from vendor's website.