kuuhana
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
  • Sign Up
Linux@programming.devbywho@feddit.org
11 months

StarDict Plugins in Debian 13 Raise Privacy Concerns

linuxiac.com English

Details: https://seclists.org/oss-sec/2025/q3/75

CVE: https://nvd.nist.gov/vuln/detail/cve-2025-55014

7
    StarDict plugins on Debian 13 leak selected X11 text over HTTP to Chinese dictionary services, exposing potentially sensitive data.
    You must log in or register to comment.

    • kbal@fedia.io
      11 months

      The package maintainer appears to be out of his mind, but now that there’s a CVE I hope it will get some attention from someone who can fix it.

      • tazeycrazy@feddit.ukEnglish
        11 months

        Do we need the internet for word definitions. How big is a dictionary. Could you not just download the dictionary?

        • Successful_Try543@feddit.org
          11 months

          Once triggered, StarDict sends the selected text in plaintext over HTTP to third-party servers in China, namely dict.youdao.com and dict.cn. And to make matters worse, these requests are made over unencrypted HTTP, making the data visible to anyone monitoring the network—whether on a local LAN or through a compromised router.

          …

          Finally, to wrap things up, it’s worth pointing out that this StarDict behavior can only happen in an X session. If you’re running Debian 13 with Wayland, then you’re safe, thanks to the protocol’s sandboxed design. And at this point, I guess folks who think Wayland is some kind of big tech conspiracy being forced on users without good reason might want to rethink that stance.

            • who@feddit.orgEnglish
              11 months

              And at this point, I guess folks who think Wayland is some kind of big tech conspiracy being forced on users without good reason might want to rethink that stance.

              Unfortunately, Wayland still lacks some functionality that Xorg has, so switching would be a step backward for some people. Snarkily dismissing them as conspiracy theorists is wrong in several ways.

                • Successful_Try543@feddit.org
                  11 months

                  Unfortunately, Wayland still lacks some things that Xorg offers, so switching would be a step backward for some people. Snarkily dismissing them as conspiracy theorists is wrong in several ways.

                  I think the intersection between those who have valid reasons to use X11, e.g. missing features of Wayland, and those wo think Wayland is a ‘big tech conspiracy’ is small.

                    • who@feddit.orgEnglish
                      11 months

                      Does the latter group exist?

                        • Successful_Try543@feddit.org
                          11 months

                          Iirc, this was recently claimed in the initial release statement of the Xlibre fork of Xorg that wants to ‘make X great again’

                  Linux@programming.dev

                  linux@programming.dev

                  Subscribe from remote instance

                  Create post

                  Report community

                  Modlog
                  You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

                  A community for everything relating to the GNU/Linux operating system (except the memes!)

                  Also, check out:

                  • !linux_memes@programming.dev
                  • !linuxphones@lemmy.ca
                  • our Matrix group chat
                  • !reactos@programming.dev

                  Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

                  Visibility: Public

                  This community is visible to everyone.

                  • 157 users / Day
                  • 1.12K users / Week
                  • 1.15K users / Month
                  • 8.57K users / 6 months
                  • 4.55K posts
                  • 36.8K comments
                  • 1 local subscriber
                  • 14.1K subscribers
                  • UI: 1.0.0-beta.0
                  • BE: 1.0.0-alpha.20
                  • Modlog
                  • Instances
                  • Docs
                  • Code
                  • join-lemmy.org