MEDIUM
stardict: network queries may expose sensitive information
Published Jun 30, 2009
5.0
MEDIUMCVSS 2.0
EPSS 2.43%
Description
stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of stardict as shipped with Red Hat Enterprise Linux 5.
Weaknesses (1)
References (9)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2025/08/04/1
- http://www.securityfocus.com/archive/1/504583 mailing-listx_refsource_BUGTRAQ
- https://access.redhat.com/security/cve/CVE-2009-2260 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=508945 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2256 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-2260
- https://www.cve.org/CVERecord?id=CVE-2009-2260
- https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00121.html vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 | x_refsource_MISC | |
| http://www.openwall.com/lists/oss-security/2025/08/04/1 | ||
| http://www.securityfocus.com/archive/1/504583 | mailing-listx_refsource_BUGTRAQ | |
| https://access.redhat.com/security/cve/CVE-2009-2260 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=508945 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2256 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-2260 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-2260 | ||
| https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00121.html | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 30, 2009
Updated Nov 4, 2025
Reserved Jun 29, 2009
Link CVE-2009-2260
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-2256 Assigner mitre
Published Jun 30, 2009
Updated Nov 4, 2025
Exploited since n/a
Link EUVD-2009-2256