Описание
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
stardict | fixed | 3.0.7+git20220909+dfsg-8 | package | |
stardict | no-dsa | trixie | package | |
stardict | no-dsa | bookworm | package |
Примечания
https://www.openwall.com/lists/oss-security/2025/08/04/1
https://lists.debian.org/debian-user/2025/08/msg00076.html
3.0.7+git20220909+dfsg-8 uploaded to unstable removes the stardict_youdaodict.so
plugin from stardict-plugin package, consider this version as the fixed version.
EPSS
Связанные уязвимости
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
EPSS