CVE-2025-55014: Medium severity youdao YouDao plugin for StarDict vulnerability
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55014?
CVE-2025-55014 is considered a medium severity vulnerability due to the transmission of sensitive data over cleartext HTTP.
How do I fix CVE-2025-55014?
To mitigate CVE-2025-55014, update to a version of the YouDao plugin for StarDict that uses HTTPS instead of HTTP.
What systems are affected by CVE-2025-55014?
CVE-2025-55014 affects the YouDao plugin for StarDict version 3.0.7+git20220909+dfsg-6 or later on Debian trixie and similar systems.
What type of data is compromised in CVE-2025-55014?
CVE-2025-55014 risks exposing X11 selection data sent to dict.youdao.com and dict.cn servers.
Is CVE-2025-55014 exploitable remotely?
Yes, CVE-2025-55014 can be exploited remotely due to its reliance on cleartext HTTP for data transmission.