First published: Tue Mar 25 2025(Updated: )
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "the only way to get an object of type GsfMSOleSortingKey is via gsf_msole_sorting_key_new which adds that extra zero element".
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
libgsf | <=1.14.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2724 is classified as problematic due to its potential for causing out-of-bounds read conditions.
To fix CVE-2025-2724, update GNOME libgsf to a version later than 1.14.53.
CVE-2025-2724 affects the function sorting_key_copy in GNOME libgsf versions up to 1.14.53.
CVE-2025-2724 can only be exploited locally on the host where the vulnerable software is installed.
CVE-2025-2724 can result in unintended out-of-bounds memory access, potentially leading to information disclosure or crashes.