CVE-2025-55014

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Configurations

No configuration.

History

13 Aug 2025, 17:15

Type Values Removed Values Added
References
  • () https://lwn.net/SubscriberLink/1032732/3334850da49689e1/ -
  • () https://news.ycombinator.com/item?id=44872313 -

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) El complemento YouDao para StarDict, tal como se usa en stardict 3.0.7+git20220909+dfsg-6 en Debian trixie y en otros lugares, envía una selección X11 a los servidores dict.youdao.com y dict.cn a través de HTTP de texto plano.

04 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 20:15

Updated : 2025-08-13 17:15


NVD link : CVE-2025-55014

Mitre link : CVE-2025-55014

CVE.ORG link : CVE-2025-55014


JSON object : View

Products Affected

No product.

CWE
CWE-402

Transmission of Private Resources into a New Sphere ('Resource Leak')