CVE-2025-2721: GNOME libgsf gsf_base64_encode_simple heap-based overflow
Published Mar 25, 2025
·Updated
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [as] the buffer pointed to by "data" must have "len" valid bytes." The documentation was fixed to make that clear.
Affected Software
1 affected component
Gnome libgsf<=1.14.53
Event History
Mar 25, 2025
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Data Sourced
via NVD·12:15 AM
Description
Apr 22, 2025
Rejected
via MITRE·12:25 PM
Rejected
via NVD·01:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2721?
CVE-2025-2721 has been classified as a critical vulnerability.
2
What is affected by CVE-2025-2721?
CVE-2025-2721 affects GNOME libgsf versions up to 1.14.53.
3
How do I fix CVE-2025-2721?
To fix CVE-2025-2721, update GNOME libgsf to the latest version available beyond 1.14.53.
4
What type of vulnerability is CVE-2025-2721?
CVE-2025-2721 is a heap-based buffer overflow vulnerability.
5
Is CVE-2025-2721 a local or remote attack vector?
CVE-2025-2721 requires a local attack approach.