CVE-2025-2724: GNOME libgsf sorting_key_copy out-of-bounds
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "the only way to get an object of type GsfMSOleSortingKey is via gsfmsolesortingkeynew which adds that extra zero element".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2724?
CVE-2025-2724 is classified as problematic due to its potential for causing out-of-bounds read conditions.
How do I fix CVE-2025-2724?
To fix CVE-2025-2724, update GNOME libgsf to a version later than 1.14.53.
What does CVE-2025-2724 affect specifically?
CVE-2025-2724 affects the function sorting_key_copy in GNOME libgsf versions up to 1.14.53.
Can CVE-2025-2724 be exploited remotely?
CVE-2025-2724 can only be exploited locally on the host where the vulnerable software is installed.
What kind of impact does CVE-2025-2724 have?
CVE-2025-2724 can result in unintended out-of-bounds memory access, potentially leading to information disclosure or crashes.