|
|
|
|
|
by jbfoo
3088 days ago
|
|
Problem is, that as far as I understand, compiler "fixes" could fix attacked application. So if JavaScript code is exploiting Spectre to read passwords from your keepassx fixes need to be applied to keepassx and not to V8 engine. (Also probably you can patch V8 interpreter to mitigate this issue, but this is a different story) |
|
KeePass uses HTTP, and by the time it sees the request, it cannot do much if it's valid.