CVE-2025-2722 - CERT CVE
ID CVE-2025-2722
Sažetak A vulnerability was found in GNOME libgsf up to 1.14.53. It has been declared as critical. This vulnerability affects the function gsf_prop_settings_collect_va. The manipulation of the argument n_alloced_params leads to heap-based buffer overflow. Local access is required to approach this attack. The vendor was contacted early about this disclosure but did not respond in any way.
Reference
CVSS
Base: 4.3
Impact: 6.4
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL PARTIAL
CVSS vektor AV:L/AC:L/Au:S/C:P/I:P/A:P
Zadnje važnije ažuriranje 27-03-2025 - 16:45
Objavljeno 25-03-2025 - 01:15