PT-2025-12685 · Gnome+1 · Gnome Libgsf+1
Ninpwn
·
Published
2025-03-24
·
Updated
2025-12-30
·
CVE-2025-2722
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
GNOME libgsf versions up to 1.14.53
Description
A critical issue affects the function
gsf prop settings collect va due to the manipulation of the argument n alloced params, leading to a heap-based buffer overflow. This issue requires local access to exploit. The vendor was contacted about this disclosure but did not respond.Recommendations
For GNOME libgsf versions up to 1.14.53, consider restricting access to the
gsf prop settings collect va function until a patch is available. As a temporary workaround, avoid manipulating the n alloced params argument to minimize the risk of exploitation.Fix
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Gnome Libgsf