CVE-2025-2723: GNOME libgsf gsf_property_settings_collec heap-based overflow
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [as] the buffer pointed to by "data" must have "len" valid bytes." The documentation was fixed to make that clear.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2723?
CVE-2025-2723 has been rated as critical due to its potential to cause a heap-based buffer overflow.
How do I fix CVE-2025-2723?
To fix CVE-2025-2723, users should update GNOME libgsf to a version later than 1.14.53.
What causes CVE-2025-2723?
CVE-2025-2723 is caused by manipulation of the n_alloced_params argument in the gsf_property_settings_collec function.
Who is affected by CVE-2025-2723?
CVE-2025-2723 affects users of GNOME libgsf versions up to and including 1.14.53.
Is local access required to exploit CVE-2025-2723?
Yes, local access is required to exploit CVE-2025-2723.