PT-2025-12686 · Gnome+1 · Gnome Libgsf+1

Ninpwn

·

Published

2025-03-24

·

Updated

2025-03-25

·

CVE-2025-2723

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GNOME libgsf versions up to 1.14.53
Description A critical issue affects the function gsf property settings collec. The manipulation of the argument n alloced params leads to a heap-based buffer overflow. This issue requires local attack capabilities. The vendor was contacted about this disclosure but did not respond.
Recommendations For GNOME libgsf versions up to 1.14.53, as a temporary workaround, consider restricting access to the gsf property settings collec function until a patch is available. Avoid manipulating the n alloced params argument in the affected function to minimize the risk of exploitation.

Fix

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07134
CVE-2025-2723

Affected Products

Debian
Gnome Libgsf