Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-55014

Опубликовано: 04 авг. 2025
Источник: debian
EPSS Низкий

Описание

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
stardictfixed3.0.7+git20220909+dfsg-8package
stardictfixed3.0.7+git20220909+dfsg-8~deb13u1trixiepackage
stardictno-dsabookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2025/08/04/1

  • https://lists.debian.org/debian-user/2025/08/msg00076.html

  • 3.0.7+git20220909+dfsg-8 uploaded to unstable removes the stardict_youdaodict.so

  • plugin from stardict-plugin package, consider this version as the fixed version.

EPSS

Процентиль: 25%
0.00084
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
6 месяцев назад

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

CVSS3: 4.7
nvd
6 месяцев назад

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

CVSS3: 4.7
github
6 месяцев назад

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

EPSS

Процентиль: 25%
0.00084
Низкий