PT-2025-12686 · Gnome+1 · Gnome Libgsf+1
Ninpwn
·
Published
2025-03-24
·
Updated
2025-03-25
·
CVE-2025-2723
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
GNOME libgsf versions up to 1.14.53
Description
A critical issue affects the function
gsf property settings collec. The manipulation of the argument n alloced params leads to a heap-based buffer overflow. This issue requires local attack capabilities. The vendor was contacted about this disclosure but did not respond.Recommendations
For GNOME libgsf versions up to 1.14.53, as a temporary workaround, consider restricting access to the
gsf property settings collec function until a patch is available. Avoid manipulating the n alloced params argument in the affected function to minimize the risk of exploitation.Fix
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Gnome Libgsf