CVE Details
Basic Information
| Title | CVE-2025-55014 |
|---|---|
| Type | cve |
| Published | 2025-08-04T00:00:00.000Z |
| Modified | 2025-08-04T20:00:45.294Z |
Product Information
| Vendor | StarDict |
|---|---|
| Product | StarDict |
| Version | 0 |
CVSS Information
| Base Score | 4.7 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N |
Affected Products
- StarDict StarDict 0
Additional Information
| CWE List | CWE-402 |
|---|---|
| Source | mitre |
Description
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
References
- https://www.openwall.com/lists/oss-security/2025/08/04/1
- https://lists.debian.org/debian-user/2025/08/msg00076.html
- https://packages.debian.org/trixie/stardict
- https://packages.debian.org/trixie/stardict-gtk
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1110370
- https://stardict-4.sourceforge.net/index_en.php