Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-55014

Опубликовано: 04 авг. 2025
Источник: debian
EPSS Низкий

Описание

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
stardictfixed3.0.7+git20220909+dfsg-8package
stardictno-dsatrixiepackage
stardictno-dsabookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2025/08/04/1

  • https://lists.debian.org/debian-user/2025/08/msg00076.html

  • 3.0.7+git20220909+dfsg-8 uploaded to unstable removes the stardict_youdaodict.so

  • plugin from stardict-plugin package, consider this version as the fixed version.

EPSS

Процентиль: 19%
0.00062
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
24 дня назад

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

CVSS3: 4.7
nvd
24 дня назад

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

CVSS3: 4.7
github
24 дня назад

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

EPSS

Процентиль: 19%
0.00062
Низкий