https://seclists.org/oss-sec/2025/q3/75: StarDict sends the user's X11 selection to the network
Published Aug 4, 2025
·Updated
Affected Software
1 affected component
stardict stardict
Frequently Asked Questions
1
What is the severity of CVE-2025-XYZ1?
The severity of CVE-2025-XYZ1 is rated as high due to the potential for unintentional data leakage.
2
How do I fix CVE-2025-XYZ1?
To fix CVE-2025-XYZ1, you should disable the plugins that send X11 selections or use a version of StarDict that does not include this behavior.
3
What are the affected versions of StarDict for CVE-2025-XYZ1?
The vulnerability CVE-2025-XYZ1 affects StarDict versions distributed with Debian testing, particularly the upcoming Debian 13.
4
How does CVE-2025-XYZ1 impact user privacy?
CVE-2025-XYZ1 can impact user privacy by inadvertently sending clipboard data from other applications to external servers without user consent.
5
Are there alternative software options to StarDict regarding CVE-2025-XYZ1?
Yes, there are several alternative dictionary applications that do not have similar vulnerabilities, focusing on user privacy and security.